Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
ID: 077cf52f-50f8-5f7c-8783-eda396d15e52
STIX ID: report--077cf52f-50f8-5f7c-8783-eda396d15e52
Feed Name: The Hacker News
Threat Score
Datadog Security Labs reports overlapping campaigns that programmatically enumerate GitHub organizations, repositories, users, gists, and related metadata via the GitHub API using aged dormant 'ghost' accounts, compromised personal access tokens/OAuth tokens, and automated tooling; while much of the activity targets public endpoints, investigators confirmed instances where attackers cloned private repositories, indicating limited successful data access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
