惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Fox-IT International blog
Recent Announcements
Recent Announcements
D
Docker
IT之家
IT之家
B
Blog
Jina AI
Jina AI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 【当耐特】
Google DeepMind News
Google DeepMind News
F
Fortinet All Blogs
量子位
C
Check Point Blog
Microsoft Azure Blog
Microsoft Azure Blog
罗磊的独立博客
博客园 - 司徒正美
李成银的技术随笔
美团技术团队
Blog — PlanetScale
Blog — PlanetScale
雷峰网
雷峰网
The GitHub Blog
The GitHub Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
J
Java Code Geeks
T
The Blog of Author Tim Ferriss
酷 壳 – CoolShell
酷 壳 – CoolShell
MongoDB | Blog
MongoDB | Blog
P
Proofpoint News Feed
L
LangChain Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Y
Y Combinator Blog
大猫的无限游戏
大猫的无限游戏
有赞技术团队
有赞技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
Visual Studio Blog
T
Tailwind CSS Blog
H
Help Net Security
Engineering at Meta
Engineering at Meta
小众软件
小众软件
B
Blog RSS Feed
Stack Overflow Blog
Stack Overflow Blog
月光博客
月光博客
M
Microsoft Research Blog - Microsoft Research
宝玉的分享
宝玉的分享
人人都是产品经理
人人都是产品经理
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
GbyAI
GbyAI
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Last Week in AI
Last Week in AI
Martin Fowler
Martin Fowler
Stack Overflow Blog
Stack Overflow Blog

Cyber Security News

Trellix Source Code Breach - Hackers Gain Unauthorized Access to Repository Hackers Breach Government and Military Servers by Exploiting cPanel Vulnerability Multiple Exim Mail Server Vulnerabilities Leads to Crash with Malicious DNS data Attackers Deploy AiTM Phishing Pages to Access SharePoint, HubSpot, and Google Workspace Attackers Abuse Google AppSheet, Netlify, and Telegram in Facebook Phishing Campaign cPanelSniper - PoC Exploit Disclosed for cPanel Vulnerability, 44,000 Servers Compromised Criminal IP and Securonix ThreatQ Collaborate to Enhance Threat Intelligence Operations EtherRAT Campaign Uses SEO Poisoning and GitHub Facades to Target Enterprise Admins The Agency Mirage: Why AI Needs Real Engineering, Not Just Hype New Spyware Platform Lets Buyers Rebrand and Resell Android Surveillance Malware Attackers Abuse CAPTCHA and ClickFix Tactics to Boost Credential Theft Campaigns New DDoS Malware Exploits Jenkins to Attack Valve Source Engine Game Servers Ubuntu Website and Canonical Web Services Hit by DDoS Attack Ransomware Victims Jump to 7,831 as AI Crime Tools Scale Global Attacks Deep#Door Stealer Harvests Browser Passwords, Cloud Tokens, SSH Keys, and Wi-Fi Credentials China-Aligned Attackers Use ShadowPad, IOX Proxy, and WMIC in Multi-Stage Espionage Campaign New Fake CAPTCHA Campaign Uses SMS Pumping Fraud to Run Up Victims’ Phone Bills Critical Wireshark Vulnerabilities Let Attackers Execute Arbitrary Code Via Malformed Packets Anthropic Launches Claude Security in Public Beta for Enterprise Customers Microsoft Windows 11 April 2026 Security Update Breaks Third-Party Backup Applications Qilin Ransomware Enumerates RDP Authentication History on a Compromised Server Targeted Large-Scale Campaign Attacking U.S. Organizations with Fake Event Invitations New PhaaS Platform Phoenix Drives Brand-Impersonation Smishing Across Finance, Telecom, and Logistics FBI and CISA Released Zero Trust Principles Implementation Guide for OT Environments Popular Python Package lightning Hacked in Supply Chain Attack Google Gemini CLI Vulnerabilities Allow Attackers to Execute Commands on Host Systems Jenkins Patches High-Severity Plugin Flaws Including Path Traversal and Stored XSS WordPress Plugin Hacked Since 2020 to Inject Malicious Code Silently OpenAI Releases 5-Point Action Plan to Strengthen AI-Powered Cyber Defense CVE MCP Server Turns Claude Into a Full-Spectrum Security Analyst With 27 Tools Across 21 APIs Claude-Generated Commit Adds PromptMink Malware to Crypto Trading Agent Qinglong Task Scheduler RCE Vulnerabilities Exploited in the Wild Novel KarstoRAT RAT Enables Webcam Monitoring, Audio Recording, and Remote Payload Execution CISA Warns of ConnectWise ScreenConnect Vulnerability Exploited in Attacks ProFTPD’s SQL Injection Vulnerability Enables Remote Code Execution Attacks Malicious npm Package Brand-Squats TanStack Exfiltrate Developer Secrets New EtherRAT Variant Uses Trojanized Tftpd64 Installer to Bridge Web2 Malware and Web3 Theft SonicWall SonicOS Vulnerabilities Allow Attackers to Bypass Access Controls and Crash Firewall Europol Busts €50 Million Online Fraud Network Running Corporate-Style Scam Call Centres cPanel 0-Day Authentication Bypass Vulnerability Actively Exploited in the Wild — PoC Released Cursor AI Extension Access Developer Tokens Leads to Full Credential Compromise Linux Kernel 0-Day "Copy Fail" Roots Every Major Distribution Since 2017 SAP npm Packages Compromised to Harvest Developer and CI/CD Secrets Lazarus Hackers Attacking macOS Users With 'Mach-O Man' Malware Kit Brinker Introduces a Novel Approach to Deepfake Detection Cursor AI Coding Agent Vulnerability Allow Attackers to Execute Code on Developer’s Machine SLOTAGENT Malware Uses API Hashing and Encrypted Strings to Hinder Reverse Engineering Minecraft Players Targeted by LofyStealer Using Node.js Loader and In-Memory Browser Injection Vimeo Confirms Data Breach - Hackers Accessed Users Database CISA Warns Microsoft Windows Shell 0-click Vulnerability Exploited in Attacks Hugging Face LeRobot Vulnerability Enables Unauthenticated RCE Attacks Critical Chrome Vulnerabilities Enables Remote Code Execution Attacks New Vect 2.0 RaaS Operation Targets Windows, Linux, and ESXi Systems New VECT 2.0 Ransomware Destroys Files Over 128 KB Across Windows, Linux, and ESXi New BlueNoroff Campaign Uses Fileless PowerShell and AI-Generated Zoom Lures cPanel Warns of Critical Authentication Flaw - Emergency Patch Released New BlobPhish Attack Leverages Browser Blob Objects to Steal Users' Login Credentials Critical GitHub.com and Enterprise Server RCE Vulnerability Enables Full Server Compromise Microsoft Confirms Remote Desktop Warnings May Display Incorrectly After April 2026 Security Update Checkmarx Confirms GitHub Repository Data Published on Dark Web Critical LiteLLM SQL Injection Vulnerability Exploited in the Wild Chinese Silk Typhoon Hacker Extradited to the U.S. from Italy WhatsApp Testing Own Cloud Backup Provider for Default End-to-End Encryption New Windows 0-Click Vulnerability Exploited to Bypass Defender SmartScreen New Silver Fox Campaign Uses Fake Tax Audit Alerts and Software Updates to Deliver Malware Chinese-Backed Smishing Services Use OTT Messaging and SMS to Scale Credential Theft Microsoft Launches Copilot Agent Mode for Outlook, Inbox and Calendar Functions New Sandworm Tradecraft Uses SSH-over-Tor Tunnel for Long-Term Hidden Persistence Popular PyPI Package With 1 Million Monthly Downloads Hacked to Inject Malicious Scripts Windows Remote Desktop Leaves Behind Image Fragments Attackers Can Stitch Into Screenshots Multiple OpenClaw Vulnerabilities Enables Policy Bypass and Host Override Linux ELF Malware Generator Evades ML Detection With Semantic-Preserving Changes OilRig Hides C2 Configuration in Google Drive Image Using LSB Steganography New Android Banking Malware Abuses Fake KYC Workflow and WhatsApp Delivery to Hijack Accounts Fake Document Reader On Google Play With 10K Downloads Installing Anatsa Malware AI Coding Agent Powered by Claude Opus 4.6 Deletes Production Database in 9 Seconds Notepad++ Vulnerability Allows Attackers to Crash Application, Leak Memory Data ClickUp's Hardcoded API Key Exposes 959 Emails from Fortune 500 Giants Critical Gemini CLI Vulnerability Enables Remote Code Execution Attacks New Vidar Malware Campaign Uses Fake YouTube Software Downloads to Steal Corporate Credentials New Malware Uses Obfuscation and Staged Payload Delivery to Evade Detection Hackers Using Fake Income Tax Department’s Notice to Deploy Malware Researchers Warn macOS textutil and KeePassXC Can Become Attack Primitives in Automation EU Proposes Requiring Google to Share User Search Data with Rival Search Engines North Korean Hackers Attacking Drug Companies to Deploy Malware Via Weaponized Excel Files ClickFix Attack Replaces PowerShell With Cmdkey and Remote Regsvr32 Payload Delivery Microsoft Outlook.com Issue Blocks Users From Accessing Emails Microsoft Officially Shares Group Policy to Remove Windows 11 Copilot from Enterprise Devices Microsoft Store App Vibing.exe Allegedly Harvested Screens, Audio, and Clipboard Content Vidar Malware Hides Second-Stage Payloads in JPEG and TXT Files to Evade Detection Attackers Can Backdoor CODESYS Applications by Chaining Vulnerabilities Top 10 Best NDR (Network Detection and Response) Solutions in 2026 'fast16' Malware with Sabotage Capabilities Attacking Ultra expensive Targets pentest-ai-agents - 28 Claude Code Subagents for Penetration Testing Nessus Agent Vulnerability on Windows Enables Arbitrary Code Execution with SYSTEM Privileges 73 Open VSX Sleeper Extensions Linked to GlassWorm Activate New Malware Campaign Litecoin Zero-Day Vulnerability Exploited in DoS Attack, Disrupts Major Mining Pools New Windows RPC Vulnerability Lets Attackers Escalate Privileges Across All Windows Versions CISA Warns of Multiple SimpleHelp Vulnerabilities Exploited in Attack Claude AI Agents Close 186 Deals in Anthropic's Marketplace Experiment
Hackers Abuse GitHub and Jira Notifications to Deliver Phishing Through Trusted SaaS Channels
2026-04-13 · via Cyber Security News

Cybercriminals are now weaponizing the very tools that developers and IT teams trust the most. By abusing the automated notification features built into GitHub and Jira, threat actors are delivering convincing phishing emails that originate directly from those platforms’ own servers.

What makes this campaign so dangerous is its simplicity. Traditional phishing relies on spoofed sender addresses or fake lookalike domains that security tools can often detect.

In this case, the emails come from verified infrastructure — real servers tied to GitHub and Atlassian, the company behind Jira.

Since these emails satisfy all standard authentication requirements, including SPF, DKIM, and DMARC, most security gateways have no technical grounds to block them.

Cisco Talos analysts tracked this growing trend and published their findings on April 7, 2026. Their data shows that on February 17, 2026 — the peak day of activity — about 2.89% of all emails from GitHub’s infrastructure were tied to this abuse.

Over a five-day window, roughly 1.20% of traffic from “noreply@github.com” included an “invoice” lure in the subject line.

Talos researchers refer to this method as the Platform-as-a-Proxy (PaaP) model. Attackers do not need to compromise any system or break into these platforms.

They simply use the existing features — repository commits, project invitations — as channels to push malicious content. The platforms handle the delivery, complete with verified signatures and trusted branding.

In nearly all observed cases, the end goal is credential harvesting. Victims are lured into clicking fake billing alerts, fraudulent support numbers, or deceptive account warnings.

Once a user hands over login credentials, attackers gain an entry point that can lead to unauthorized access, account takeovers, and deeper network compromise.

How the Attack Works: GitHub and Jira Notification Pipelines

On GitHub, the attack begins with creating a repository. The attacker then pushes a commit with message fields loaded with social engineering content. GitHub’s commit interface has two text areas: a short mandatory summary line and a longer optional description.

The attacker places an urgent-sounding hook — such as a fake invoice or billing alert — in the summary, and fills the extended description with the full scam message, including fake phone numbers or fraudulent links.

When the commit is submitted, GitHub automatically notifies all collaborators via email, with the full message embedded in the notification body.

Email header (Source - Cisco Talos)
Email header (Source – Cisco Talos)

The resulting email appears as a standard GitHub notification. The raw email headers in confirm the sending server as “out-28.smtp.github.com” — a legitimate GitHub mail server with IP “192.30.252.211.”

The body of the message (Source - Cisco Talos)
The body of the message (Source – Cisco Talos)

The DKIM signature carries “d=github.com” and passes all checks without raising any security flag.

Raw headers (Source - Cisco Talos)
Raw headers (Source – Cisco Talos)

The Jira approach uses a different mechanism. Attackers create a Jira Service Management project, setting a fake name — such as “Argenta” — and embedding their phishing message inside the “Welcome Message” or “Project Description” field.

Using the “Invite Customers” feature, they submit the target’s email address. Atlassian’s backend then generates an automated invite email, wrapping the attacker’s content inside its own signed and branded template.

The body of the message and the footer branding (Source - Cisco Talos)
The body of the message and the footer branding (Source – Cisco Talos)

The email arrives looking exactly like an official Jira system notification, complete with Atlassian’s branding footer.

Cisco Talos recommends that organizations shift away from blindly trusting SaaS platform emails.

Security teams should integrate GitHub and Atlassian API audit logs into a SIEM or SOAR system to flag unusual activity — such as mass user invitations or project creation from unfamiliar locations — before any phishing email is sent.

Any notification carrying financial or urgency-driven content from platforms like GitHub or Jira should be flagged for review, as that content conflicts with those tools’ intended purpose.

For sensitive interactions, users should navigate directly to the official platform portal rather than clicking notification links.

Organizations are also encouraged to automate takedown reports to platform Trust and Safety teams to raise the operational cost for attackers.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.