Ghost Accounts Abuse GitHub API in Mass Recon Campaign
Multiple campaigns are using ghost accounts to map GitHub organizations, including their repositories and members. The post Ghost Accounts Abuse GitHub API in Mass Recon Campaign appeared first on SecurityWeek.
Threat actors are abusing the GitHub API to systematically enumerate organizations, repositories, and user accounts, Datadog reports.
Spanning multiple overlapping campaigns, the activity has been ongoing for several months, relying on ghost accounts that were registered two to five years ago but left dormant.
The activity, Datadog says, involves automated scanners, the abuse of leaked credentials, and coordinated networks of dormant accounts.
Source: https://www.securityweek.com/ghost-accounts-abuse-github-api-in-mass-recon-campaign/
Related breach coverage
- Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials2026-07-27
A threat actor has been using the compromised appliances to target the Microsoft 365 accounts of traveling corporate employees. The post Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials appeared first on SecurityWeek.
- Clover Health Investments Discloses Data Breach2026-07-21
Using social engineering, hackers compromised employee accounts with access to personal and health information. The post Clover Health Investments Discloses Data Breach appeared first on SecurityWeek.
- Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking2026-08-03
Midnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations. The post Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking appeared first on SecurityWeek.
- Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations2026-07-31
A security company’s systems were hacked after it installed a malicious Python package deployed by Claude. The post Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations appeared first on SecurityWeek.