Weekend lead:The keyv/cacheable npm worm changes the order of containmentVishing extortion shifts the control problem to personal phones…Atuin can preserve Linux shell evidence that standard history…Self-evolving agent skills create a trajectory-poisoning control gap
Front page · Monday intelligence
The keyv/cacheable npm worm changes the order of containment
A self-propagating package compromise reaches developer workstations and CI runners, while a token-validity watcher makes isolation and evidence preservation precede credential revocation.
By Security.io Intelligence Desk · Executive analysis
Treat a match as a potential credential and publishing-identity compromise, not merely a dependency problem. The payload can execute through installation or repository-opening hooks, establish host persistence and trigger an attacker-controlled command when a stolen GitHub token is revoked.
Why today: The compromise began on August 4, before the requested window. What changes Monday’s decision is the operational analysis showing propagation across trusted package paths, execution when a repository is merely opened, and a watcher that can turn routine…
“Isolate matched developer endpoints and CI runners without powering them off.”
Decision owner: CISO, supported by the incident-response lead, VP Engineering, developer-platform owner and cloud identity team
Decision horizon: Immediate: first four hours, followed by a 24-hour credential and publishing-integrity review
Treat a match as a potential credential and publishing-identity compromise, not merely a dependency problem. The payload can execute through installation or repository-opening hooks, establish host…
Monday action: Isolate matched developer endpoints and CI runners without powering them off.
UNC6671 callers use urgent passkey or MFA-enrolment pretexts on employees’ personal phones, directing targets to adversary-in-the-middle portals. Successful sessions support automated SaaS data access, password resets…
Monday action: Warn targeted staff that helpdesk teams do not conduct passkey enrolment through…
Linux incident playbooks that collect only .bash_history or .zsh_history can miss richer Atuin evidence. The database records command context and can retain soft-deleted or write-ahead-log artefacts…
Monday action: Add Atuin artefact discovery to Linux triage procedures.
The research demonstrates a control problem in agents that learn reusable skills from stored trajectories: apparently successful experience can become a poisoned instruction source.
Monday action: Inventory agents that retain trajectories or generate reusable skills.
A single Cowrie sensor observed scripted post-authentication behaviour completing in seconds after a weak root password succeeded.
Monday action: Identify every internet-accessible SSH service and accountable owner.
Signal desk
Interactive editorial evidence
Security.io editorial assessment
Lead decision pressure
Hover or tap a bar for its exact value and the editorial meaning behind it. Keyboard: focus the chart and use ↑ or ↓.
Scores are Security.io editorial ratings from 0–100 for the lead decision, based on package reach, credential access, response-order sensitivity and potential downstream propagation; they are not external measurements.
Hover or tap a point to see the story title, new references, cumulative evidence, source mix and why the story entered today’s edition. Keyboard: use ← or →.
This line shows cumulative cited references across the lead and four supporting briefs.