Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
The Compliance Brief · Issue 9

Patch NetScaler, then check your subprocessors

Free weekly email

This went to subscribers on October 6. Get the next one.

One email every Tuesday: what changed in security and compliance that week, and what it means if you sell to enterprise buyers.

Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.

Quiet week for headlines, busier week for anything you actually have to do something about. Two items here need action from an engineering team this week, and the other three change how a US buyer's security reviewer is going to read your answers. I have left out the municipal ransomware and the hospital breaches, which are sad and have nothing to teach a SaaS company in Toronto.

Cyber Centre updates its NetScaler alert again

Source: Cyber Centre (CCCS)

The Canadian Centre for Cyber Security issued alert AL26-024 on September 27 covering two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-88771 and CVE-2026-88772. The alert was updated again on October 3. It is addressed to IT professionals and managers, with detection and mitigation advice.

Our take

When the Cyber Centre updates the same alert twice inside a week, that usually means the situation on the ground is moving rather than the paperwork. If you have a NetScaler in front of anything, patch it and then go looking for signs it was already touched, because applying an update does not undo access somebody already has. I have seen enough internet-facing appliances during assessments to say this plainly: the gateway is the part of the stack that gets owned, and it is almost never the part anyone has an owner for.

Frontline Education breached through someone else's software

Source: BleepingComputer

Frontline Education is notifying school districts that attackers exploited a vulnerability in third-party software to reach its systems and steal employee information, including Social Security numbers. The affected people are staff at Frontline's customer districts, not Frontline's own employees.

Our take

This is the shape of incident that most damages a B2B vendor, because the people harmed are your customer's people and your customer has to tell them. Pull your subprocessor list this week and read what your own contracts actually commit you to when one of your vendors is the one that gets hit, including how many hours you have to notify and who signs the notice. Most of the Canadian teams I work with can produce the list, and very few can produce the notification clock from memory.

AWS agent tooling can leak credentials

Source: Infosecurity

Researchers reported flaws in the Amazon Bedrock AgentCore SDK that could allow an attacker to run commands inside AI sandboxes and reach AWS credentials. The issue sits in the agent runtime layer rather than in a customer's own application code.

Our take

If you shipped an AI feature in the last year, it probably got a lighter design review than the rest of your product, and the credentials behind it are probably broader than they need to be. Treat the agent runtime as an untrusted execution environment: separate account, scoped role, no long-lived keys sitting where the model can see them. US buyers have started adding agent questions to their security questionnaires, and "we use Bedrock" is not an answer to any of them.

An arrest, then an escalation

Source: Krebs on Security

Dutch police arrested a 23-year-old convicted cybercriminal suspected of helping ShinyHunters with data thefts and extortion. In the days after the arrest, the remaining members escalated, stealing data from the FBI and extorting the Russian ransomware group Cl0p.

Our take

Police action against this crowd reads well and changes very little about your exposure, as the week after the arrest demonstrated. ShinyHunters makes its money pulling customer records out of SaaS platforms and connected business applications, which is a precise description of what your production database holds. The control that matters is boring and unglamorous: tight scoping on OAuth integrations, detection on bulk export, and an honest answer to how much data one compromised support account can pull.

Your exception register is a security document

Source: The Hacker News

A piece aimed at banks, insurers and asset managers walks through the familiar cycle where security wants a class of vulnerabilities gone, engineering prices out the platform upgrade and regression testing, the change-freeze calendar gets raised, and the finding ends up with an exception, a compensating control and a date.

Our take

Fintech readers will recognise this because their own customers run the same cycle, and it is why enterprise security reviewers now ask to see the exception list rather than the clean scan. An exception with a named owner, a stated compensating control and a date that has not moved twice is defensible in a SOC 2 audit and in a buyer call. One that has rolled over three quarters tells the reviewer something about your engineering culture, and it is never the thing you wanted it to say.

Short list this week because most of what came through the feeds was someone else's bad month. The NetScaler item is the one I would handle before Wednesday.

Jacob

Share this issue LinkedIn X Email

Free weekly email

Get the next issue on Tuesday

One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.

Free. Unsubscribe in one click, and replies reach Jacob directly.

Go deeper

Every past issue · RSS feed