Coordinated GitHub API Enumeration and Access Token Abuse (Campaign)
ID: ddf52e15-7a9c-5ee3-bbaa-e5e7ebdf1e42
STIX ID: report--ddf52e15-7a9c-5ee3-bbaa-e5e7ebdf1e42
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2026-07-08
Date Updated: 2026-07-19
Author: [email protected] (Wiz Threat Research)
Datadog Security Labs identified multiple coordinated campaigns abusing GitHub APIs and legitimate credentials (including dormant 'ghost' accounts and valid PATs/OAuth tokens) to systematically enumerate organizations, repositories, users, and development activity at scale; although much of the activity focused on public-repo reconnaissance, some cases of compromised credentials allowed unauthorized access to private repositories, increasing supply-chain and intelligence-gathering risk on GitHub.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
