❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 11 August 2026SANS Internet Storm Center, InfoCON: green

Scans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th)

Solana is a crypto platform known for speed. Developers like it to develop distributed applications or to implement crypto payments. To interact with the blockchain, APIs are provided for developers. These APIs will either "speak" JSON or gRPC. One implementation often used for development is "surfpool," which is used to test programs before deploying them to a Solana network.
Yesterday β€” 10 August 2026SANS Internet Storm Center, InfoCON: green
Before yesterdaySANS Internet Storm Center, InfoCON: green

Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)

UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they definitely lack of "modern"Β logging: shells. Most shells provide an historization of the typed commands through a flat file in the $HOME directory (ex: $HOME/.bash_history). They suffer of multiple problems:

Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)

When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle the cloud keys. That reflex has been correct in almost every supply-chain incident I have worked. In theΒ keyv/cacheableΒ compromise that has been unfolding since yesterday, it is the one thing you should not do first β€” because revoking the stolen token is exactly what arms the payload.
❌
❌