Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
The Compliance Brief · Issue 7

Fake government requests, real AI attacks

Free weekly email

This went to subscribers on September 22. Get the next one.

One email every Tuesday: what changed in security and compliance that week, and what it means if you sell to enterprise buyers.

Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.

Five things came through this week that actually touch how you get through a US security review, and a few of them are about access nobody thought to revoke. The Revolut disclosure is the one I would read twice if you work in fintech, because the failure was in a process most companies have never written down. The rest are ordinary hygiene problems that keep showing up in real incidents.

Revolut handed over customer data to someone pretending to be a government

Source: Infosecurity

Revolut confirmed that an unauthorized party obtained customer information by submitting a fraudulent data request from a legitimate government email domain. Personal and financial details were disclosed to the requester. Follow-on phishing aimed at Revolut customers is now being reported.

Our take

Almost every fintech I work with has a path for law enforcement and regulator requests, and almost none of them can show me the verification steps or the log of what was released. A compromised or spoofed government domain beats a process that relies on the email looking official, so the control has to be out-of-band confirmation with the agency plus a record of every field disclosed. Write that procedure down now, because once a US buyer reads this story it becomes a question in your next review.

A regulator has now logged an AI agent as the attacker

Source: SecurityWeek

The Spanish data protection agency received a breach report describing an attack carried out by an AI agent running on a known large language model. Regulators say the agent chained a successful login, discovery of a vulnerability, and access to personal data.

Our take

This changes nothing about your obligations and quite a lot about your assumptions. Most detection tuning quietly assumes a human pace between login, poking around, and pulling data, and an agent collapses that into minutes. I would go look at whether your alerting on a valid session doing unusual reads fires at machine speed or at the speed of somebody reviewing a weekly report.

A departed employee's GitHub account was still live, and 170 private repos walked

Source: The Hacker News

CrowdSec disclosed that an attacker copied roughly 170 of its private GitHub repositories in May using the account of an employee who had recently left the company. The company had left that GitHub access open. CrowdSec says the former employee's laptop was compromised in the TanStack npm supply chain attack earlier that month.

Our take

Offboarding is the SOC 2 control where I see the most theatre. The HR ticket gets closed, the SSO account gets disabled, and the GitHub org, the cloud console, the CI tokens and the personal access tokens survive because they were never tied to the identity provider in the first place. If a security company can miss this, run your own check today rather than trusting the termination checklist someone filled in retroactively.

Exposed Vite dev servers are being scanned for cloud keys

Source: The Hacker News

F5 Labs described an automated mass-scanning campaign hunting internet-exposed Vite development servers. The goal is to pull AWS and Azure credentials, configuration files and infrastructure state files from those hosts.

Our take

Development and preview environments get written out of audit scope constantly, and infrastructure state files are exactly where long-lived keys and connection strings sit. Ask your team whether any Vite dev server has ever been reachable from the internet, and if the answer is anything other than a confident no, rotate what was on that box. Scope on paper does not protect an IP address that answers on the public internet.

OCR is still writing cheques for Security Rule failures

Source: HIPAA Journal

The HHS Office for Civil Rights announced a settlement with Ambry Genetics over potential violations of the HIPAA Security Rule. Ambry will pay a $700,000 penalty.

Our take

For Canadian SaaS teams who signed a business associate agreement to close a US healthcare deal, this is the enforcement arm you inherited along with the contract. Seven hundred thousand dollars is survivable for a genetics lab and is not survivable for a 60-person company, and OCR does not adjust for the fact that you are in Toronto. If you hold PHI, the Security Rule work needs to be real documentation rather than a policy pack you bought.

Three of this week's five stories come down to credentials that outlived their purpose. That is a boring conclusion, and it is still where most of the damage happens.

Jacob

Share this issue LinkedIn X Email

Free weekly email

Get the next issue on Tuesday

One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.

Free. Unsubscribe in one click, and replies reach Jacob directly.

Go deeper

Every past issue · RSS feed