logo

Phishers sneak through using GitHub and Jira’s own mail delivery infrastructure

ID: a44607d5-b8c0-5876-ba71-70eaa5880a0b

STIX ID: report--a44607d5-b8c0-5876-ba71-70eaa5880a0b

Feed Name: Help Net Security

Threat Score
70/100

Date Published: 2026-04-09

Date Updated: 2026-04-28

Author: Sinisa Markovic

...
...

Cisco Talos warns that attackers are abusing GitHub and Jira notification systems to send phishing and spam that bypass SPF/DKIM/DMARC because emails originate from the platforms' own infrastructure; attackers inject malicious content via commit messages on GitHub or Jira's Invite Customers and project fields so the phishing appears in trusted, branded system-generated notifications, with Cisco observing up to 2.89% of GitHub emails tied to this abuse on a peak day.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.