The “Seal of Approval” Trap: How Hackers are Hijacking GitHub and Jira Notifications
ID: 18018275-c2f8-5be1-b853-b251911d6904
STIX ID: report--18018275-c2f8-5be1-b853-b251911d6904
Feed Name: securityonline.info
Cisco Talos observed attackers abusing trusted notification systems in collaboration platforms (GitHub and Jira) in a technique called Platform-as-a-Proxy (PaaP), where malicious content is delivered via legitimate platform-generated emails—bypassing SPF/DKIM/DMARC and leveraging organizational trust—to carry out phishing and credential-harvesting scams (e.g., malicious commit messages on GitHub and deceptive Jira invites); defenders are urged to rethink SaaS traffic monitoring as signature-based filtering is insufficient.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
