McKesson breach came through third-party applications
September 1, 2026. From issue 4 of The Compliance Brief, 2 stories for companies buying a SOC 2 audit.
Issue 4 of The Compliance Brief was published on September 1, 2026. 2 of its 5 stories bear on SOC 2 audits, auditors and vendor reviews, and they are below in short form. The full issue, with every take in full, is on traztech.ca.
Free weekly email
Get the next issue on Tuesday
One email a week: what changed in security and compliance, and what it means for companies buying a SOC 2 audit.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.
Source: BleepingComputer
McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft. The ShinyHunters extortion group claims it took 284 million patient records, a figure that comes from the attackers and not from McKesson.
Our take, in short
Ignore the record count, which is unverified and usually inflated, and look at the entry point. Connected SaaS applications with broad OAuth scopes keep being the way into large healthcare and finance environments, which is exactly the risk your prospect is thinking about when they classify you as a critical vendor.
Read the full take on traztech.ca
JFrog Artifactory flaw lands in the KEV catalogue
Source: CISA
CISA added three actively exploited vulnerabilities to the Known Exploited Vulnerabilities catalogue: an ownCloud authentication flaw, an unspecified Linux kernel issue, and a path traversal issue in JFrog Artifactory. The catalogue is tied to CISA's binding directive on prioritizing security updates by risk for federal agencies.
Our take, in short
Artifactory is the interesting one for this audience because it usually sits inside the build environment with credentials to everything downstream. You are not a US federal agency, but plenty of your customers now write KEV remediation timelines into their vendor contracts, and auditors have started asking how you learn a KEV entry exists at all.
Read the full take on traztech.ca
Related on GetSOC2
- What a SOC 2 report looks like
- SOC 2 for SaaS companies in Canada
- Security questionnaire readiness
- Why your customer is asking for SOC 2
Also in issue 4
Outside SOC 2 audits, auditors and vendor reviews, but in the same email:
- CISA red-teamed two organizations and only one saw it coming
- Two arrests in the TeamPCP open-source supply chain spree
- Cyber claims are fewer and far more expensive
Older: issue 3 All issues on GetSOC2 Newer: issue 5
Free weekly email
Get it every Tuesday
The next issue goes out Tuesday morning. Read it in your inbox instead of finding it here a week later.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.