A departed employee's GitHub account was still live, and 170 private repos walked
September 22, 2026. From issue 7 of The Compliance Brief, 2 stories for founders and executives who own security.
Issue 7 of The Compliance Brief went to subscribers on September 22, 2026. 2 of its 5 stories bear on breaches, incidents and security leadership, and they are below in short form. The full issue, with every take in full, is on traztech.ca.
Free weekly email
Get the next issue on Tuesday
One email a week: what changed in security and compliance, and what it means for founders and executives who own security.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.
Source: The Hacker News
CrowdSec disclosed that an attacker copied roughly 170 of its private GitHub repositories in May using the account of an employee who had recently left the company. The company had left that GitHub access open.
Our take, in short
Offboarding is the SOC 2 control where I see the most theatre. The HR ticket gets closed, the SSO account gets disabled, and the GitHub org, the cloud console, the CI tokens and the personal access tokens survive because they were never tied to the identity provider in the first place.
Read the full take on traztech.ca
Revolut handed over customer data to someone pretending to be a government
Source: Infosecurity
Revolut confirmed that an unauthorized party obtained customer information by submitting a fraudulent data request from a legitimate government email domain. Personal and financial details were disclosed to the requester.
Our take, in short
Almost every fintech I work with has a path for law enforcement and regulator requests, and almost none of them can show me the verification steps or the log of what was released. A compromised or spoofed government domain beats a process that relies on the email looking official, so the control has to be out-of-band confirmation with the agency...
Read the full take on traztech.ca
Related on HireACISO
- Our biggest deal is blocked on security
- vCISO for a Canadian fintech
- Do you need a vCISO? A six question check
- Fractional or full-time: which fits now
Also in issue 7
Outside breaches, incidents and security leadership, but in the same email:
- A regulator has now logged an AI agent as the attacker
- Exposed Vite dev servers are being scanned for cloud keys
- OCR is still writing cheques for Security Rule failures
Older: issue 6 All issues on HireACISO Newer: issue 8
Free weekly email
Get it every Tuesday
The next issue goes out Tuesday morning. Read it in your inbox instead of finding it here a week later.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.