The Compliance Brief for cloud teams
Every Tuesday, the cloud incidents from the past week, from exposed storage to stolen tokens, and what to check in your own AWS, Azure or Google Cloud account.
Most cloud incidents are not exotic. They are a bucket left public, a key committed to a repository, or a token nobody revoked. The Compliance Brief picks out the ones that happened this week and says what to check in your own account.
Below are the stories from recent issues that bear on cloud security and compliance, each with the short version and a link to the full take.
Free weekly email
Get the next issue on Tuesday
Join the list and the next issue arrives Tuesday morning. Or read a few below first.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.
Latest on cloud security, misconfiguration and data residency
- A stolen OAuth token from a former employee's laptop
CrowdSec confirmed that attackers took the contents of 170 private repositories from its GitHub organisation. - Exposed Vite dev servers are being scanned for cloud keys
F5 Labs described an automated mass-scanning campaign hunting internet-exposed Vite development servers. - Microsoft patches a 10.0 in Entra ID
Microsoft patched CVE-2026-69836, a remote code execution flaw in Entra ID carrying a CVSS score of 10.0, which was initially reported as exploited in the wild. - An AWS key in a public JavaScript bundle took down 1,000 charity CRMs
CRM provider Beacon disclosed a breach affecting more than 1,000 UK charities. - The LiteLLM fallout is a CI credential problem, not an AI problem
A 153GB archive stolen in the LiteLLM supply chain attack has surfaced, containing 433,909 files.
Every issue on CloudCompliance
- Issue 8: A stolen OAuth token from a former employee's laptop
- Issue 7: Exposed Vite dev servers are being scanned for cloud keys
- Issue 3: Microsoft patches a 10.0 in Entra ID
- Issue 2: An AWS key in a public JavaScript bundle took down 1,000 charity CRMs
Every issue in full, including the stories outside cloud security, misconfiguration and data residency, is in the archive on traztech.ca. Issues with nothing on cloud security, misconfiguration and data residency are listed there and not here.
Questions
How often does The Compliance Brief arrive?
Once a week, on Tuesday morning. Each issue covers the past week in five stories or so, with what happened and a short take on what it means for Canadian companies running on AWS, Azure or Google Cloud.
What does it cost?
Nothing. It is written by Jacob Masse, Principal at TrazTech Inc., which operates CloudCompliance. There is no paid tier.
Will signing up here send me anything else?
No. The form on this page adds you to The Compliance Brief and nothing else. Downloading a checklist elsewhere on the site is a separate signup, and it says what it sends before you give an address.
How do I stop it?
Every issue ends with a one-click unsubscribe link, and it is honoured immediately. Replying to any issue also reaches Jacob directly.
Free weekly email
Get it every Tuesday
One email a week on cloud security, misconfiguration and data residency. Free, and one click to leave.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.