Threat Actors Exploit GitHub and Jira Messages For Phishing Delivery
ID: a254b847-4be4-56b9-846d-976ba7bd1e14
STIX ID: report--a254b847-4be4-56b9-846d-976ba7bd1e14
Feed Name: Cyber Press
Cisco Talos warns that threat actors are hijacking GitHub and Jira notifications to deliver phishing lures that inherit the platforms' valid SPF/DKIM/DMARC authentication, allowing malicious messages to bypass reputation-based email filters; the report recommends treating SaaS-originated notifications as untrusted until verified at the instance and user level, implementing instance-level authorization, ingesting SaaS audit logs into SIEM/SOAR, adding friction to high-risk workflows, and automating takedown/reporting to reduce Platform-as-a-Proxy (PaaP) abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
