Hackers Abuse GitHub and Jira Notifications to Deliver Phishing Through Trusted SaaS Channels
ID: e7e7001a-9807-5b24-8bd0-e59f7ca36f84
STIX ID: report--e7e7001a-9807-5b24-8bd0-e59f7ca36f84
Feed Name: cybersecurityNews.com
This report describes a phishing campaign that weaponizes legitimate GitHub and Jira automated notifications: attackers embed fraudulent billing/invoice and support content into commit messages or project descriptions so the platforms’ own signed emails deliver convincing phishing messages that bypass SPF/DKIM/DMARC checks and aim to harvest credentials; Cisco Talos observed notable traffic spikes and recommends logging platform API/audit activity, flagging atypical notifications, and directing users to verify directly on the platform.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
