GetPentest

The Compliance Brief for security testing

Every Tuesday, the vulnerabilities being exploited that week and what they mean for the scope of your next penetration test.

Last reviewed 2026-09-29Written by Jacob Masse, TrazTech Inc.

A penetration test is a snapshot, and the list of what attackers are actually using changes every week. The Compliance Brief tracks it: new entries on the known exploited list, exposed services being scanned at scale, and the flaws that turned into breaches.

Below are the stories from recent issues that bear on security testing, each with the short version and what to check or add to the next test's scope.

Latest on exploited vulnerabilities and security testing

Every issue on GetPentest

Every issue in full, including the stories outside exploited vulnerabilities and security testing, is in the archive on traztech.ca. Issues with nothing on exploited vulnerabilities and security testing are listed there and not here.

Questions

How often does The Compliance Brief arrive?

Once a week, on Tuesday morning. Each issue covers the past week in five stories or so, with what happened and a short take on what it means for teams that commission penetration tests.

What does it cost?

Nothing. It is written by Jacob Masse, Principal at TrazTech Inc., which operates GetPentest. There is no paid tier.

Will signing up here send me anything else?

No. The form on this page adds you to The Compliance Brief and nothing else. Downloading a checklist elsewhere on the site is a separate signup, and it says what it sends before you give an address.

How do I stop it?

Every issue ends with a one-click unsubscribe link, and it is honoured immediately. Replying to any issue also reaches Jacob directly.