An AWS key in a public JavaScript bundle took down 1,000 charity CRMs
August 18, 2026. From issue 2 of The Compliance Brief, 2 stories for Canadian companies running on AWS, Azure or Google Cloud.
Issue 2 of The Compliance Brief went to subscribers on August 18, 2026. 2 of its 5 stories bear on cloud security, misconfiguration and data residency, and they are below in short form. The full issue, with every take in full, is on traztech.ca.
Free weekly email
Get the next issue on Tuesday
One email a week: what changed in security and compliance, and what it means for Canadian companies running on AWS, Azure or Google Cloud.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.
Source: SecurityWeek
CRM provider Beacon disclosed a breach affecting more than 1,000 UK charities. The suspected root cause was a compromised AWS access key that had been exposed in publicly available JavaScript build artifacts.
Our take, in short
This is one of the most common findings I get on web application tests, and it is almost never in the source repository where the scanner is pointed. It gets baked into the built bundle, or into a sourcemap that ships to production alongside it.
Read the full take on traztech.ca
The LiteLLM fallout is a CI credential problem, not an AI problem
Source: Help Net Security
A 153GB archive stolen in the LiteLLM supply chain attack has surfaced, containing 433,909 files. Hudson Rock attributed 118,829 CI runner dumps to 2,488 corporate domains, with credentials tied to AWS, Samsung, Cisco and Salesforce among them.
Our take, in short
CI runner dumps are the worst possible thing to lose, because build environments tend to hold the credentials nobody wants to rotate: cloud keys, registry tokens, signing material, production database strings. If you added an LLM gateway or proxy to your stack in the last year, treat every secret that environment could read as burned and rotate on that basis...
Read the full take on traztech.ca
Related on CloudCompliance
- AWS KMS, Key Vault and Cloud KMS compared
- Cloud key management decider
- Cloud secrets management for compliance
- Common cloud audit findings
Also in issue 2
Outside cloud security, misconfiguration and data residency, but in the same email:
- Metabase SQL injection is now on the KEV list
- A year-long campaign is quietly draining Salesforce and ServiceNow tenants
- When the subprocessor is breached, your customer writes the letter with your name in it
All issues on CloudCompliance Newer: issue 3
Free weekly email
Get it every Tuesday
The next issue goes out Tuesday morning. Read it in your inbox instead of finding it here a week later.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.