A session or a key proves the past, and two stories this week act on that
Most access control rests on an assumption that is easy to forget: a valid credential means the right person is acting. Two items this week are about the gap between those two things.
Checking at the moment of action. GitHub's new proof of presence, in preview for managed-user enterprises on Entra ID, sends a member back to their identity provider before high-impact actions - creating tokens, editing webhooks, changing organisation security settings. GitHub's stated reason is that stolen session cookies and long-lived tokens keep appearing in supply-chain attacks. A session proves that someone authenticated earlier; the new check asks whether the right person is present now.
Assuming everything was read. LuaRocks.org found that a remote code execution flaw had been exploited on its server since July. Its response was to treat everything the server could touch as exposed: every API key revoked, every session ended, stored 2FA secrets removed, password hashes declared exposed, and all third-party credentials rotated. It did not try to work out which credentials had actually been read. Once code ran on the server, the answer was "all of them".

The common idea
Both treat a credential as a record of something that happened, not as proof about the present. A cookie records a login; an API key records a decision to grant access; a 2FA secret records an enrolment. Each can be copied without the owner knowing, and a copy is indistinguishable from the original. The only defences are to ask again at the moments that matter, or to invalidate the record when there is reason to think it has been copied.
What to take from it
For teams running their own systems, three habits follow. Make high-impact actions require a fresh check, even if the session is valid; token creation and webhook changes are the steps attackers use to stay. Keep credentials short-lived where possible, so that a stolen copy expires on its own. And have a rehearsed "revoke everything" procedure: LuaRocks could rotate all credentials and verify packages because it had a daily mirror stored off the server - a precaution taken long before it was needed.