A $1 billion law firm last week learned a critical cybersecurity lesson: Even something as innocuous as the ceiling on the number of packages allowed in GitHub can increase an enterprise’s threat profile by undercutting the least privilege principle. When the problem was initially discovered early this month, it presented the consulting firm handling the…
