← Back to the feed

~/article/don-t-revoke-that-token-yet-inside-the-keyv-cacheable-npm-worm-wed-aug-5-c907qw
infoSource: SANS Internet Storm Center

Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)

When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle the cloud keys. That reflex has been correct in almost every supply-chain incident I have worked. In the keyv / cacheable compromise that has been unfolding since yesterday, it is the one thing you should not do first — because revoking…

Read at the source

Summary written for cymesh.dev. The full article lives at SANS Internet Storm Center.

~/cymesh.net

Certificates expire quietly

cymesh.net watches your TLS and SSL certificates and warns you before one lapses.

monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks