Red Hat npm Packages Compromised in Supply Chain Attack
Submitted 1 week ago by cm0002@lemy.lol to cybersecurity@infosec.pub
https://linuxiac.com/red-hat-npm-packages-compromised-in-supply-chain-attack/
Submitted 1 week ago by cm0002@lemy.lol to cybersecurity@infosec.pub
https://linuxiac.com/red-hat-npm-packages-compromised-in-supply-chain-attack/
tal@lemmy.today 1 week ago
This doesn’t solve the problem of people storing credentials where credential-stealers can steal them, but it’s not a bad idea to periodically invalidate your credentials and generate new ones, even if you don’t know that they’ve been compromised, just on the off change that someone has grabbed yours and has them stored up, ready to use them at some point in the future.
That’s especially true if you develop or package software (and thus users of your software trust you to keep their systems secure) or have administrator access to any networks or multiuser systems (and thus your users trust you to keep their data secure).