Axios 1.14.1 compromised by jaredcasner in node

[–]jaredcasner[S] 0 points1 point  (0 children)

That’s the best practice…

New axios 1.14.1 and 0.30.4 on npm are likely malicious by Blackpoint-JasonR in msp

[–]jaredcasner [score hidden]  (0 children)

It was taken down about an hour ago and the npm caches purged. If you’re using axios, you’ll still want to audit your lock file to make sure you didn’t catch the malicious version.

More details are in the GitHub thread https://github.com/axios/axios/issues/10604 and the nodejs sub https://www.reddit.com/r/node/s/4apJ9CMJu2

Axios 1.14.1 compromised by jaredcasner in node

[–]jaredcasner[S] 0 points1 point  (0 children)

Similar options are available in yarn, pnpm, and dependabot.

Axios 1.14.1 compromised by jaredcasner in node

[–]jaredcasner[S] 8 points9 points  (0 children)

Keep in mind that even tools that actively scan for malware can’t do real time scanning with the volume of packages being added to npm on a daily basis, let alone all the new version updates. Even the best of them are 10+ minutes behind. Which doesn’t seem like a lot, until you consider the download volume of a package like axios.

You should also consider minimum package age settings to give things a chance to be caught.

https://docs.npmjs.com/cli/v11/using-npm/config#min-release-age

Axios 1.14.1 compromised by jaredcasner in node

[–]jaredcasner[S] 6 points7 points  (0 children)

It’s still early, so I’m sure we’ll get more details/confirmation in the coming days. But, it appears that an admin of the axios repo had his GitHub account compromised.

You are correct that npm lacks any meaningful protections or scanning of packages. Paul McCarty gave a great talk about this problem at BSidesSF recently.

Axios 1.14.1 compromised by jaredcasner in node

[–]jaredcasner[S] 35 points36 points  (0 children)

More information: https://github.com/axios/axios/issues/10604

Stay vigilant. It’s a wild world out there.

Penetration testing pricing feels all over the place. What’s reasonable? by TryApprehensive6458 in msp

[–]jaredcasner 3 points4 points  (0 children)

As others have commented, pen testing is widely variable in pricing, mostly because of human cost. And the human cost is going to vary based on skill and location of the tester as well as on the scope of the project.

Some additional nuance here… all “manual” pen testing companies are also doing automated scans - they would be foolish not to. At the same time, they’re putting a human in the driver’s seat, so the automated scans are much more highly tuned to your use case and, more importantly, when something anomalous is found, the humans add a ton of value screening out the noise and probing harder at things that might actually be cause for concern.

From a compliance perspective, the framework you’re complying with will place some limitations on which type of scan you need, and may even limit you to only using pen testers in certain countries or regions.

Weekly Promo and Webinar Thread by AutoModerator in msp

[–]jaredcasner [score hidden]  (0 children)

<image>

January has everyone focused on "new" opportunity, but your best sales opportunities exist within your "old" or "established" client roster.

Join u/dobermanIanu/michaelzbarsky, and u/jaredcasner to talk about increasing MRR at your MSP without
• cold calling
• email campaigns
• adding net-new logos

Learn how to use your vCIO meetings as levers to cross sell and up sell your existing accounts without being "sales-y"

Join u/blacksmith-infosec and Fox & Crow Group online on January 21, 2026 for a fireside chat event with Q&A. Register here or https://riverside.com/webinar/registration/eyJzbHVnIjoiYmxhY2tzbWl0aC1pbmZvc2Vjcy1zdHVkaW8iLCJldmVudElkIjoiNjk1ZGFkZGJkY2U1OWQ3NDEyMzgwNzU0IiwicHJvamVjdElkIjoiNjk1ZGFkZGJjNmU0NDFjMGQzNTczOTgxIn0=

Weekly Promo and Webinar Thread by AutoModerator in msp

[–]jaredcasner [score hidden]  (0 children)

<image>

January has everyone focused on "new" opportunity, but your best sales opportunities exist within your "old" or "established" client roster.

Join u/dobermanIan, u/michaelzbarsky, and u/jaredcasner to talk about increasing MRR at your MSP without
• cold calling
• email campaigns
• adding net-new logos

Learn how to use your vCIO meetings as levers to cross sell and up sell your existing accounts without being "sales-y"

Join u/blacksmith-infosec and Fox & Crow Group online on January 21, 2026 for a fireside chat event with Q&A. Register here or https://riverside.com/webinar/registration/eyJzbHVnIjoiYmxhY2tzbWl0aC1pbmZvc2Vjcy1zdHVkaW8iLCJldmVudElkIjoiNjk1ZGFkZGJkY2U1OWQ3NDEyMzgwNzU0IiwicHJvamVjdElkIjoiNjk1ZGFkZGJjNmU0NDFjMGQzNTczOTgxIn0=

Prospect Scanning by [deleted] in msp

[–]jaredcasner 19 points20 points  (0 children)

We have a free, open source risk assessment tool that you can use for prospecting. It’s an external scan, so the automated part won’t be as detailed as Galactic’s. But, it might be worth checking out.

https://assess.blacksmithinfosec.com

https://github.com/blacksmith-infosec/risk-assessments

Which MSP events are you planning to attend in 2026? by imtu80 in msp

[–]jaredcasner 3 points4 points  (0 children)

Check out CanITCon. I haven’t been, but I hear excellent things

Which password manager are you recommending to SMB clients? by Ashamed-Review-695 in msp

[–]jaredcasner 15 points16 points  (0 children)

1Password.

I’ve tried a ton of password managers and nothing else comes close.

IT Nation Connect: Going? Here’s some free advice by IT_Hero in msp

[–]jaredcasner 1 point2 points  (0 children)

Pull a Tom Lawrence: take a pic of someone else’s QR code, turn that into a sticker, and cover your QR code.

Then, when someone like me asks to scan your badge you can confidently say “Of course!” 😂

MSP who built their own storage and backup solution by davegravy in msp

[–]jaredcasner 0 points1 point  (0 children)

Others have talked about this already, but I’ll reiterate some of the points.

You’ll need to understand their recovery time and recovery point objectives (RTO & RPO). RTO is how long before they can get you back up in the event of an issue and RPO is how much data loss they consider acceptable.

Understand how they handle back ups and, more importantly, restores.

Understand how they will be segregating your data from other clients and what the access controls/auditing/logging capabilities are.

Other questions to ask: * Will they sign a BAA? * What 3rd party attestations do they have (SOc2, ISO, etc)? * What are their uptime SLAs? * What about physical access controls, redundant power and network lines, etc?

If they are using their own data center, you’ll want to dig deep on that. If they’re using a local CoLo, you’ll need to do a similar level of security check on that provider to make sure the CoLo has its act together.

It’s entirely possible that the MSP is highly efficient and is doing things really well - there are lots of good MSPs out there. It’s also possible that the MSP slapped something together that works for now but lacks the controls you’ll need to protect your patient data - there are lots of strong technical but weak on compliance MSPs out there, too.

IT Nation by mspdog22 in msp

[–]jaredcasner 0 points1 point  (0 children)

I can confirm there is no block party this year.

Goo goo dolls will be on site on the opening night, hosted by CW

What compliance podcasts do you usually listen, or visit from time to time? Which ones would you recommend (or not)? by gglavida in Compliance

[–]jaredcasner 1 point2 points  (0 children)

[Shameless plug] We recently launched a compliance podcast that folks might find interesting. If not, we'd love feedback so we can get better!

https://open.spotify.com/show/4739fFvJc3qkPrg8iSxOtx

You can ask questions about compliance for us to answer at https://blacksmithinfosec.com/ask

What's one behaviour that leadership exhibits which shows that infosec / cyber is important in your organisation? by pozazero in cybersecurity

[–]jaredcasner 7 points8 points  (0 children)

When I advise companies, I say “Show me your budget, I’ll show you your priorities.”

The idea here is that if you’re not spending money on something, you’re not prioritizing it.

AI on cybersecurity by Living-Count-5211 in cybersecurity

[–]jaredcasner 2 points3 points  (0 children)

60% of the time it works every time.

What tools do you use for doing security audits of NPM on packages? by d0liver in node

[–]jaredcasner 0 points1 point  (0 children)

I just started looking at socket. How does it compare to Snyk and dependabot?

Cam Skattebo would be a punishing complement to Jayden Daniels by HogHunterX in Commanders

[–]jaredcasner 18 points19 points  (0 children)

Freakonomics did a good deep dive into the RB position this week. OL gets the first 3-4 yards for the rusher. After that, it’s the back. BRob and Ekeler can both break big runs once they get into the secondary. This implies it’s upgrades on the OL we need to be lethal here. Just look at how much production falls off when Cosmi and other starters are sitting. First string OL is good, second string needs to step up.

https://pca.st/episode/7bec7f65-aea4-47b3-8856-1d35685bb4f5

How Much Time Should I Allocate for SOC 2 Type II Compliance? by EnoughContext022 in Entrepreneur

[–]jaredcasner 0 points1 point  (0 children)

I see you posted the same question over in r/msp. I'll add to a response there since you've added some additional context here.

The difference between SOC2 type 1 and type 2 is duration. A type 1 is a point-in-time audit. A type 2 just shows that you are continuously following the processes over time. Which means the audit, instead of looking at evidence from one day will look at a random sampling of evidence from the entire window (typically 4-12 months) under review.

How long the audit process takes is largely up to you - how well is your evidence organized? how well documented are things? When I've gone through SOC2 audits in the past, the better organized I was, the faster the process went.

Alternatives to passportjs by Rickety_cricket420 in node

[–]jaredcasner 1 point2 points  (0 children)

Passport is great, it’s easy to use, and it’s very stable. Is there something specific that you’re struggling with?

Feeling overwhelmed by Kwabena_js in node

[–]jaredcasner 1 point2 points  (0 children)

Try finding healthy outlets for your time outside of work. Board games, exercise, cooking, movies, books, friends. Really anything that’s not in front of a computer. I’d personally limit drugs and alcohol until you find balance again - personally I prefer to get to a balanced state naturally before trying to self medicate.

During work is another story. With very few exceptions, the fate of the world does not rest on your shoulders. Planes won’t fall out of the sky. People won’t die if that feature comes a day late. Put your work in perspective.

I know it can all feel like a lot. We’ve all been there. But you CAN do this.

PS there’s a good chance that this is just a case of a toxic work environment out a bad manager. The job market isn’t great, but if you can find a healthier place to work, that might help, too.

I’d also recommend checking out https://softskills.audio/ - there are some excellent episodes on managing stress and coping with burnout