<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>The Compliance Brief on ISO27K</title>
    <link>https://iso27k.ca/brief</link>
    <atom:link href="https://iso27k.ca/brief/feed.xml" rel="self" type="application/rss+xml"/>
    <description>A free weekly email for ISO 27001 and ISO 42001 teams in Canada: supplier incidents, AI risk and the week&#x27;s stories that belong in a risk register.</description>
    <language>en-CA</language>
    <item>
      <title>Your AI agents are logging in as humans and SOC 2 cannot tell</title>
      <link>https://iso27k.ca/brief/8-patch-netscaler-then-read-the-labcorp-terms</link>
      <guid isPermaLink="true">https://iso27k.ca/brief/8-patch-netscaler-then-read-the-labcorp-terms</guid>
      <pubDate>Tue, 29 Sep 2026 13:00:00 +0000</pubDate>
      <description>Your AI agents are logging in as humans and SOC 2 cannot tell. A vendor-authored piece argues that AI agents often operate through human credentials, so actions taken by an agent look identical to actions taken by the person whose credentials it borrowed.</description>
    </item>
    <item>
      <title>A regulator has now logged an AI agent as the attacker</title>
      <link>https://iso27k.ca/brief/7-fake-government-requests-real-ai-attacks</link>
      <guid isPermaLink="true">https://iso27k.ca/brief/7-fake-government-requests-real-ai-attacks</guid>
      <pubDate>Tue, 22 Sep 2026 13:00:00 +0000</pubDate>
      <description>A regulator has now logged an AI agent as the attacker. The Spanish data protection agency received a breach report describing an attack carried out by an AI agent running on a known large language model.</description>
    </item>
    <item>
      <title>Trezor&#x27;s supplier breach keeps growing, and it was never Trezor&#x27;s system</title>
      <link>https://iso27k.ca/brief/6-revolut-handed-data-to-a-fake-government-request</link>
      <guid isPermaLink="true">https://iso27k.ca/brief/6-revolut-handed-data-to-a-fake-government-request</guid>
      <pubDate>Tue, 15 Sep 2026 13:00:00 +0000</pubDate>
      <description>Trezor&#x27;s supplier breach keeps growing, and it was never Trezor&#x27;s system. Trezor says a breach at its supplier ShipMonk is considerably worse than first reported, now affecting around 81,000 customers.</description>
    </item>
    <item>
      <title>AI coding agents are pulling packages nobody registered</title>
      <link>https://iso27k.ca/brief/5-court-records-drivers-licences-and-an-ftc-bill</link>
      <guid isPermaLink="true">https://iso27k.ca/brief/5-court-records-drivers-licences-and-an-ftc-bill</guid>
      <pubDate>Tue, 08 Sep 2026 13:00:00 +0000</pubDate>
      <description>AI coding agents are pulling packages nobody registered. Researchers scanned 6,214 live domains belonging to defence contractors, Fortune 500 and large tech companies and found 8,265 llms.txt and llms-full.txt files. McKesson tells the SEC it was hit through third-party applications. McKesson disclosed a cybersecurity incident in which attackers got into third-party applications and stole data, with the intrusion detected on August 25, 2026.</description>
    </item>
    <item>
      <title>McKesson breach came through third-party applications</title>
      <link>https://iso27k.ca/brief/4-what-cisas-two-red-teams-say-about-your-soc-2</link>
      <guid isPermaLink="true">https://iso27k.ca/brief/4-what-cisas-two-red-teams-say-about-your-soc-2</guid>
      <pubDate>Tue, 01 Sep 2026 13:00:00 +0000</pubDate>
      <description>McKesson breach came through third-party applications. McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft.</description>
    </item>
    <item>
      <title>The LiteLLM fallout is a CI credential problem, not an AI problem</title>
      <link>https://iso27k.ca/brief/2-secrets-in-build-artifacts-and-who-gets-blamed</link>
      <guid isPermaLink="true">https://iso27k.ca/brief/2-secrets-in-build-artifacts-and-who-gets-blamed</guid>
      <pubDate>Tue, 18 Aug 2026 13:00:00 +0000</pubDate>
      <description>The LiteLLM fallout is a CI credential problem, not an AI problem. A 153GB archive stolen in the LiteLLM supply chain attack has surfaced, containing 433,909 files.</description>
    </item>
    <item>
      <title>Hidden prompt injection is showing up in &quot;Ask AI&quot; buttons on marketing pages</title>
      <link>https://iso27k.ca/brief/1-a-250-000-penalty-and-a-vendor-that-went-dark</link>
      <guid isPermaLink="true">https://iso27k.ca/brief/1-a-250-000-penalty-and-a-vendor-that-went-dark</guid>
      <pubDate>Tue, 11 Aug 2026 13:00:00 +0000</pubDate>
      <description>Hidden prompt injection is showing up in &quot;Ask AI&quot; buttons on marketing pages. Researchers observed production websites embedding hidden prompt injection payloads inside pre-filled deep links behind &quot;Ask AI&quot; buttons, including on marketing and competitor comparison pages. LexisNexis pulled products offline over a third-party vendor incident. LexisNexis took several services offline, including Diligence and the Metabase API, in response to unusual activity on servers hosted and managed by a third-party vendor it has not named. Gunra ransomware is getting in through firewalls, per a joint advisory. US and South Korean agencies issued a joint advisory on Gunra, a ransomware-as-a-service operation that has been breaching organizations by exploiting vulnerabilities in Fortinet and Schneider Electric products.</description>
    </item>
  </channel>
</rss>
