Ghost Accounts Abuse GitHub API in Mass Recon Campaign
Threat actors have been systematically scanning and mapping GitHub organizations, repositories, and user accounts using a network of dormant “ghost” accounts. The abuse of GitHub’s API has been ongoing for several months, with multiple overlapping campaigns using leaked credentials and automated scanners to gather information. The activity, discovered by cybersecurity firm Datadog, involves exploiting publicly … Read more