logo

Hackers Abuse GitHub and Jira Notifications to Deliver Phishing Through Trusted SaaS Channels

ID: e7e7001a-9807-5b24-8bd0-e59f7ca36f84

STIX ID: report--e7e7001a-9807-5b24-8bd0-e59f7ca36f84

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2026-04-13

Date Updated: 2026-05-08

Author: Tushar Subhra Dutta

...
...

This report describes a phishing campaign that weaponizes legitimate GitHub and Jira automated notifications: attackers embed fraudulent billing/invoice and support content into commit messages or project descriptions so the platforms’ own signed emails deliver convincing phishing messages that bypass SPF/DKIM/DMARC checks and aim to harvest credentials; Cisco Talos observed notable traffic spikes and recommends logging platform API/audit activity, flagging atypical notifications, and directing users to verify directly on the platform.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.