CloudCompliance

A stolen OAuth token from a former employee's laptop

September 29, 2026. From issue 8 of The Compliance Brief, one story for Canadian companies running on AWS, Azure or Google Cloud.

Last reviewed 2026-09-29Written by Jacob Masse, TrazTech Inc.

Issue 8 of The Compliance Brief went to subscribers on September 29, 2026. One of its 5 stories bears on cloud security, misconfiguration and data residency, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: Dark Reading

CrowdSec confirmed that attackers took the contents of 170 private repositories from its GitHub organisation. The token used was an OAuth token stolen from a former employee's computer through the TanStack npm supply chain compromise earlier this year.

Our take, in short

Offboarding at most companies this size disables the account and stops there, leaving OAuth grants, personal access tokens and CI credentials alive behind it. Pull the list of third-party OAuth apps authorised against your GitHub organisation this week and see how many you recognise.

Read the full take on traztech.ca

Also in issue 8

Outside cloud security, misconfiguration and data residency, but in the same email:

Older: issue 7 All issues on CloudCompliance