بازگشت به اخبار
اخبار امنیت (RSS)
منبع: SANS ISC
Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)
When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle the cloud keys. That reflex has been correct in almost every supply-chain incident I have worked. In the keyv / cacheable compromise that has been unfolding since yesterday, it is the one thing you should not do first — because revoking the stolen token is exactly what arms the payload. 
۱۴۰۵/۰۵/۱۸
اخبار امنیت (RSS)
این خبر از منبع خارجی «SANS ISC» بازنشر شده است.
برای مطالعه متن کامل به صفحه اصلی خبر مراجعه کنید.