Fake “Security Alert” issues on GitHub use OAuth app to hijack accounts

Fake “Security Alert” issues on GitHub use OAuth app to hijack accounts











A widespread phishing campaign has targeted nearly 12,000 GitHub repositories with fake “Security Alert” issues, tricking developers into authorizing a malicious OAuth app that grants attackers full control over their accounts and code. […]






Lawrence Abrams





Go to bleepingcomputer





Posted

in

,

by