Don’t Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)

When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle the cloud keys. That reflex has been correct in almost every supply-chain incident I have worked. In the keyv/cacheable compromise that has been unfolding since yesterday, it is the one thing you should not do first — because revoking the stolen token is exactly what arms the payload.

Continue reading Don’t Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)

Posted in Uncategorized

Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)

Most phishing campaigns rely on the fact that the victim is afraid to loose “something”: money, access to information, … Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.

Continue reading Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)

Posted in Uncategorized