logo

The “Seal of Approval” Trap: How Hackers are Hijacking GitHub and Jira Notifications

ID: 18018275-c2f8-5be1-b853-b251911d6904

STIX ID: report--18018275-c2f8-5be1-b853-b251911d6904

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-04-10

Date Updated: 2026-04-23

Author: Ddos

...
...

Cisco Talos observed attackers abusing trusted notification systems in collaboration platforms (GitHub and Jira) in a technique called Platform-as-a-Proxy (PaaP), where malicious content is delivered via legitimate platform-generated emails—bypassing SPF/DKIM/DMARC and leveraging organizational trust—to carry out phishing and credential-harvesting scams (e.g., malicious commit messages on GitHub and deceptive Jira invites); defenders are urged to rethink SaaS traffic monitoring as signature-based filtering is insufficient.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.