Ghost Accounts Abuse GitHub API in Mass Recon Campaign
Multiple campaigns are using ghost accounts to map GitHub organizations, including their repositories and members. The post Ghost Accounts Abuse GitHub API in Mass Recon Campaign appeared first on SecurityWeek.
Threat actors are abusing the GitHub API to systematically enumerate organizations, repositories, and user accounts, Datadog reports.
Spanning multiple overlapping campaigns, the activity has been ongoing for several months, relying on ghost accounts that were registered two to five years ago but left dormant.
The activity, Datadog says, involves automated scanners, the abuse of leaked credentials, and coordinated networks of dormant accounts.
Source: https://www.securityweek.com/ghost-accounts-abuse-github-api-in-mass-recon-campaign/
Related breach coverage
- Beacon Security Raises $13 Million for Security Data Platform2026-07-17
The startup helps organizations detect, hunt, and protect their assets across environments at machine speed. The post Beacon Security Raises $13 Million for Security Data Platform appeared first on SecurityWeek.
- Risk Ledger Raises $32 Million in Series B Funding2026-07-17
The British firm has built a collaborative platform to help organizations address supply chain security risks. The post Risk Ledger Raises $32 Million in Series B Funding appeared first on SecurityWeek.
- Splunk, Zoom Patch Critical Vulnerabilities2026-07-16
The flaws could allow attackers to access credentials and data, take over accounts, and escalate their privileges. The post Splunk, Zoom Patch Critical Vulnerabilities appeared first on SecurityWeek.
- F5 Patches Multiple NGINX, BIG-IP Vulnerabilities2026-07-16
Attackers could exploit the bugs to modify configurations, terminate or restart processes, cross security boundaries, leak memory, and execute code. The post F5 Patches Multiple NGINX, BIG-IP Vulnerabilities appeared first on SecurityWeek.
