The Compliance Brief for security testing
Every Tuesday, the vulnerabilities being exploited that week and what they mean for the scope of your next penetration test.
A penetration test is a snapshot, and the list of what attackers are actually using changes every week. The Compliance Brief tracks it: new entries on the known exploited list, exposed services being scanned at scale, and the flaws that turned into breaches.
Below are the stories from recent issues that bear on security testing, each with the short version and what to check or add to the next test's scope.
Free weekly email
Get the next issue on Tuesday
Join the list and the next issue arrives Tuesday morning. Or read a few below first.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.
Latest on exploited vulnerabilities and security testing
- Eight NetScaler flaws, two already being exploited
Citrix disclosed eight vulnerabilities in NetScaler ADC and NetScaler Gateway, and CISA added two of them to the Known Exploited Vulnerabilities catalogue. - Exposed Vite dev servers are being scanned for cloud keys
F5 Labs described an automated mass-scanning campaign hunting internet-exposed Vite development servers. - Artifactory auth bypasses are now on the exploited list
CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalogue on September 11. - JFrog Artifactory flaw lands in the KEV catalogue
CISA added three actively exploited vulnerabilities to the Known Exploited Vulnerabilities catalogue: an ownCloud authentication flaw, an unspecified Linux kernel issue, and a path traversal issue in JFrog Artifactory. - CISA red-teamed two organizations and only one saw it coming
CISA ran simultaneous red team assessments at two organizations and published the comparison. - Microsoft patches a 10.0 in Entra ID
Microsoft patched CVE-2026-69836, a remote code execution flaw in Entra ID carrying a CVSS score of 10.0, which was initially reported as exploited in the wild. - Hidden prompt injection is showing up in "Ask AI" buttons on marketing pages
Researchers observed production websites embedding hidden prompt injection payloads inside pre-filled deep links behind "Ask AI" buttons, including on marketing and competitor comparison pages.
Every issue on GetPentest
- Issue 8: Eight NetScaler flaws, two already being exploited
- Issue 7: Exposed Vite dev servers are being scanned for cloud keys
- Issue 6: Artifactory auth bypasses are now on the exploited list
- Issue 4: JFrog Artifactory flaw lands in the KEV catalogue
- Issue 3: Microsoft patches a 10.0 in Entra ID
- Issue 1: Hidden prompt injection is showing up in "Ask AI" buttons on marketing pages
Every issue in full, including the stories outside exploited vulnerabilities and security testing, is in the archive on traztech.ca. Issues with nothing on exploited vulnerabilities and security testing are listed there and not here.
Questions
How often does The Compliance Brief arrive?
Once a week, on Tuesday morning. Each issue covers the past week in five stories or so, with what happened and a short take on what it means for teams that commission penetration tests.
What does it cost?
Nothing. It is written by Jacob Masse, Principal at TrazTech Inc., which operates GetPentest. There is no paid tier.
Will signing up here send me anything else?
No. The form on this page adds you to The Compliance Brief and nothing else. Downloading a checklist elsewhere on the site is a separate signup, and it says what it sends before you give an address.
How do I stop it?
Every issue ends with a one-click unsubscribe link, and it is honoured immediately. Replying to any issue also reaches Jacob directly.
Free weekly email
Get it every Tuesday
One email a week on exploited vulnerabilities and security testing. Free, and one click to leave.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.