رفتن به محتوای اصلی
بازگشت به اخبار
اخبار امنیت (RSS) منبع: SANS ISC

Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)

When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle the cloud keys. That reflex has been correct in almost every supply-chain incident I have worked. In the keyv / cacheable compromise that has been unfolding since yesterday, it is the one thing you should not do first — because revoking the stolen token is exactly what arms the payload. 

۱۴۰۵/۰۵/۱۸
اخبار امنیت (RSS)
When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle the cloud keys. That reflex has been correct in almost every supply-chain incident I have worked. In the keyv / cacheable compromise that has been unfolding since yesterday, it is the one thing you should not do first — because revoking the stolen token is exactly what arms the payload.

این خبر از منبع خارجی «SANS ISC» بازنشر شده است.

برای مطالعه متن کامل به صفحه اصلی خبر مراجعه کنید.

مشاهده منبع اصلی