{"id":12093,"date":"2026-04-14T10:04:35","date_gmt":"2026-04-14T10:04:35","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/14\/hackers-abuse-github-and-jira-notifications-to-deliver-phishing-through-trusted-saas-channels\/"},"modified":"2026-04-14T10:04:35","modified_gmt":"2026-04-14T10:04:35","slug":"hackers-abuse-github-and-jira-notifications-to-deliver-phishing-through-trusted-saas-channels","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/14\/hackers-abuse-github-and-jira-notifications-to-deliver-phishing-through-trusted-saas-channels\/","title":{"rendered":"Hackers Abuse GitHub and Jira Notifications to Deliver Phishing Through Trusted SaaS Channels"},"content":{"rendered":"<p>    Hackers Abuse GitHub and Jira Notifications to Deliver Phishing Through Trusted SaaS Channels<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cybercriminals are now weaponizing the very tools that developers and IT teams trust the most. By abusing the automated notification features built into GitHub and Jira, threat actors are delivering convincing phishing emails that originate directly from those platforms\u2019 own servers.<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/8e6e0e54-cec0-4b3c-b33c-e79af01cbc0f\/Hackers-Abuse-GitHub-and-Jira-Notifications-to-Deliver-Phishing-Through-Trusted-SaaS-Channels.pdf?AWSAccessKeyId=ASIA2F3EMEYEU4UJ73NP&amp;Signature=FczBxoLGd8hDvOJMzCK%2BVthsjQM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEK7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCSca9owkx42QL6PAh5m%2BTMRxJobbK9SWdemA%2Fh1%2BDH%2BwIgO8%2F1HGBTK8nt%2BfIH8g9ARtpW9NJUUp2m4rw9JqBUvIEq8wQIdxABGgw2OTk3NTMzMDk3MDUiDIRSMOrPTFzfkWEF3CrQBJR0TmrMHRmBAwCvkh5EWzCCE94DFobUSADRIZX%2FxCK2TfaEq%2FaJEp19DvFxOZgLrtADi7%2BI5Fg5%2BjvMr0DqMrUsHf8%2FwC%2FTHc6PtuZDxiGvW%2FXPztR6c8IblG7gjfY3oHM%2FzNt3vHc%2FeBLc%2FWaK45hzmh3XIqGpYtE804XQoYeGwkMjJ706WRkE%2FPVNFwQ%2FaEq8APbp2VHbdINwSsKyQQgyNtmJnUnns4637UWoc2EO6lRPl%2B8bNiShUmZTBuNIXSyRB0RIVDhi3lV3sskJhGSwyFr5vF%2FlOr9LVYJSK4nUMzlV3khdn6Z9pinytteGikRvvJe2H8B0avzZLKftZEqlBE1znIEisPMgaklkQzg6mrwzQxoshONRWHvrbews%2BGjDl0%2FHLouXPFpGWl6bGgN%2BlINO7OzGLMIMz9kojUKr7HmITEfhPBfH1%2BxWNtTW3LUy9WFt%2F3UPVCigj476gbbjdYpoPA786DWeH6AHZQ3pIwXBkQ27OqiURlCPfCP%2BquCqgKBY6MU8EAffKFR8S%2Bjh%2Fg4xG06rGoBnwEn76PSb6F1LarDOqt7dUWvQR9FOb3zHTZPOiieGfJZiRG9q5s%2FfY9QGH5CThLTU3iGpdNiUZEzhUFQHE35nGjwQoml%2Fh%2FBG9oSHhgw%2BU6uxefcVYOVaEgdTlTLQtcLCb6cSeTRMX%2FOxwfCajLdZ8ZamPDRbmcC6BaL9H3qLnkeW4H6QiwUKRRrbh2T1apaUw%2B6CfH8bt8gBdfz%2B3bjgEoQUg%2Bk0EuEhA5q5ClmzaU%2B8c8K30CswquzzzgY6mAHRlHxdDMCSUhwg6RvLYh5V9YBUVWH%2BaBbghvKhmDxEn5pMYvZtrJ%2Bf7IpzwmYggFt6zWLyUCwthBmHG6bkijQsqn4SwALqwX8GH3itg40r9gAC0RVCqFKyFLXkzdfUI46jBizkeABpeaxzf4%2FOQvdrQv2QvZ%2BJ8beKVvg65j7PQDpOVo%2BN2fIvrm6duXDC%2FOL3ouWcOxLqdQ%3D%3D&amp;Expires=1776091291\"><\/a><\/p>\n<p>What makes this campaign so dangerous is its simplicity. Traditional phishing relies on spoofed sender addresses or fake lookalike domains that security tools can often detect. <\/p>\n<p>In this case, the emails come from verified infrastructure \u2014 real servers tied to GitHub and Atlassian, the company behind Jira. <\/p>\n<p>Since these emails satisfy all standard authentication requirements, including SPF, DKIM, and DMARC, most security gateways have no technical grounds to block them.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/8e6e0e54-cec0-4b3c-b33c-e79af01cbc0f\/Hackers-Abuse-GitHub-and-Jira-Notifications-to-Deliver-Phishing-Through-Trusted-SaaS-Channels.pdf?AWSAccessKeyId=ASIA2F3EMEYEU4UJ73NP&amp;Signature=FczBxoLGd8hDvOJMzCK%2BVthsjQM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEK7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCSca9owkx42QL6PAh5m%2BTMRxJobbK9SWdemA%2Fh1%2BDH%2BwIgO8%2F1HGBTK8nt%2BfIH8g9ARtpW9NJUUp2m4rw9JqBUvIEq8wQIdxABGgw2OTk3NTMzMDk3MDUiDIRSMOrPTFzfkWEF3CrQBJR0TmrMHRmBAwCvkh5EWzCCE94DFobUSADRIZX%2FxCK2TfaEq%2FaJEp19DvFxOZgLrtADi7%2BI5Fg5%2BjvMr0DqMrUsHf8%2FwC%2FTHc6PtuZDxiGvW%2FXPztR6c8IblG7gjfY3oHM%2FzNt3vHc%2FeBLc%2FWaK45hzmh3XIqGpYtE804XQoYeGwkMjJ706WRkE%2FPVNFwQ%2FaEq8APbp2VHbdINwSsKyQQgyNtmJnUnns4637UWoc2EO6lRPl%2B8bNiShUmZTBuNIXSyRB0RIVDhi3lV3sskJhGSwyFr5vF%2FlOr9LVYJSK4nUMzlV3khdn6Z9pinytteGikRvvJe2H8B0avzZLKftZEqlBE1znIEisPMgaklkQzg6mrwzQxoshONRWHvrbews%2BGjDl0%2FHLouXPFpGWl6bGgN%2BlINO7OzGLMIMz9kojUKr7HmITEfhPBfH1%2BxWNtTW3LUy9WFt%2F3UPVCigj476gbbjdYpoPA786DWeH6AHZQ3pIwXBkQ27OqiURlCPfCP%2BquCqgKBY6MU8EAffKFR8S%2Bjh%2Fg4xG06rGoBnwEn76PSb6F1LarDOqt7dUWvQR9FOb3zHTZPOiieGfJZiRG9q5s%2FfY9QGH5CThLTU3iGpdNiUZEzhUFQHE35nGjwQoml%2Fh%2FBG9oSHhgw%2BU6uxefcVYOVaEgdTlTLQtcLCb6cSeTRMX%2FOxwfCajLdZ8ZamPDRbmcC6BaL9H3qLnkeW4H6QiwUKRRrbh2T1apaUw%2B6CfH8bt8gBdfz%2B3bjgEoQUg%2Bk0EuEhA5q5ClmzaU%2B8c8K30CswquzzzgY6mAHRlHxdDMCSUhwg6RvLYh5V9YBUVWH%2BaBbghvKhmDxEn5pMYvZtrJ%2Bf7IpzwmYggFt6zWLyUCwthBmHG6bkijQsqn4SwALqwX8GH3itg40r9gAC0RVCqFKyFLXkzdfUI46jBizkeABpeaxzf4%2FOQvdrQv2QvZ%2BJ8beKVvg65j7PQDpOVo%2BN2fIvrm6duXDC%2FOL3ouWcOxLqdQ%3D%3D&amp;Expires=1776091291\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p><a href=\"https:\/\/blog.talosintelligence.com\/weaponizing-saas-notification-pipelines\/\" id=\"https:\/\/blog.talosintelligence.com\/weaponizing-saas-notification-pipelines\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Cisco Talos analysts tracked this growing trend<\/a> and published their findings on April 7, 2026. Their data shows that on February 17, 2026 \u2014 the peak day of activity \u2014 about 2.89% of all emails from GitHub\u2019s infrastructure were tied to this abuse. <\/p>\n<p>Over a five-day window, roughly 1.20% of traffic from \u201cnoreply@github.com\u201d included an \u201cinvoice\u201d lure in the subject line.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/8e6e0e54-cec0-4b3c-b33c-e79af01cbc0f\/Hackers-Abuse-GitHub-and-Jira-Notifications-to-Deliver-Phishing-Through-Trusted-SaaS-Channels.pdf?AWSAccessKeyId=ASIA2F3EMEYEU4UJ73NP&amp;Signature=FczBxoLGd8hDvOJMzCK%2BVthsjQM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEK7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCSca9owkx42QL6PAh5m%2BTMRxJobbK9SWdemA%2Fh1%2BDH%2BwIgO8%2F1HGBTK8nt%2BfIH8g9ARtpW9NJUUp2m4rw9JqBUvIEq8wQIdxABGgw2OTk3NTMzMDk3MDUiDIRSMOrPTFzfkWEF3CrQBJR0TmrMHRmBAwCvkh5EWzCCE94DFobUSADRIZX%2FxCK2TfaEq%2FaJEp19DvFxOZgLrtADi7%2BI5Fg5%2BjvMr0DqMrUsHf8%2FwC%2FTHc6PtuZDxiGvW%2FXPztR6c8IblG7gjfY3oHM%2FzNt3vHc%2FeBLc%2FWaK45hzmh3XIqGpYtE804XQoYeGwkMjJ706WRkE%2FPVNFwQ%2FaEq8APbp2VHbdINwSsKyQQgyNtmJnUnns4637UWoc2EO6lRPl%2B8bNiShUmZTBuNIXSyRB0RIVDhi3lV3sskJhGSwyFr5vF%2FlOr9LVYJSK4nUMzlV3khdn6Z9pinytteGikRvvJe2H8B0avzZLKftZEqlBE1znIEisPMgaklkQzg6mrwzQxoshONRWHvrbews%2BGjDl0%2FHLouXPFpGWl6bGgN%2BlINO7OzGLMIMz9kojUKr7HmITEfhPBfH1%2BxWNtTW3LUy9WFt%2F3UPVCigj476gbbjdYpoPA786DWeH6AHZQ3pIwXBkQ27OqiURlCPfCP%2BquCqgKBY6MU8EAffKFR8S%2Bjh%2Fg4xG06rGoBnwEn76PSb6F1LarDOqt7dUWvQR9FOb3zHTZPOiieGfJZiRG9q5s%2FfY9QGH5CThLTU3iGpdNiUZEzhUFQHE35nGjwQoml%2Fh%2FBG9oSHhgw%2BU6uxefcVYOVaEgdTlTLQtcLCb6cSeTRMX%2FOxwfCajLdZ8ZamPDRbmcC6BaL9H3qLnkeW4H6QiwUKRRrbh2T1apaUw%2B6CfH8bt8gBdfz%2B3bjgEoQUg%2Bk0EuEhA5q5ClmzaU%2B8c8K30CswquzzzgY6mAHRlHxdDMCSUhwg6RvLYh5V9YBUVWH%2BaBbghvKhmDxEn5pMYvZtrJ%2Bf7IpzwmYggFt6zWLyUCwthBmHG6bkijQsqn4SwALqwX8GH3itg40r9gAC0RVCqFKyFLXkzdfUI46jBizkeABpeaxzf4%2FOQvdrQv2QvZ%2BJ8beKVvg65j7PQDpOVo%2BN2fIvrm6duXDC%2FOL3ouWcOxLqdQ%3D%3D&amp;Expires=1776091291\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Talos researchers refer to this method as the Platform-as-a-Proxy (PaaP) model. Attackers do not need to compromise any system or break into these platforms. <\/p>\n<p>They simply use the existing features \u2014 repository commits, project invitations \u2014 as channels to push <a href=\"https:\/\/cybersecuritynews.com\/beware-malicious-content-being-served-via-archive-org\/\" id=\"7013\" target=\"_blank\" rel=\"noreferrer noopener\">malicious content<\/a>. The platforms handle the delivery, complete with verified signatures and trusted branding.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/8e6e0e54-cec0-4b3c-b33c-e79af01cbc0f\/Hackers-Abuse-GitHub-and-Jira-Notifications-to-Deliver-Phishing-Through-Trusted-SaaS-Channels.pdf?AWSAccessKeyId=ASIA2F3EMEYEU4UJ73NP&amp;Signature=FczBxoLGd8hDvOJMzCK%2BVthsjQM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEK7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCSca9owkx42QL6PAh5m%2BTMRxJobbK9SWdemA%2Fh1%2BDH%2BwIgO8%2F1HGBTK8nt%2BfIH8g9ARtpW9NJUUp2m4rw9JqBUvIEq8wQIdxABGgw2OTk3NTMzMDk3MDUiDIRSMOrPTFzfkWEF3CrQBJR0TmrMHRmBAwCvkh5EWzCCE94DFobUSADRIZX%2FxCK2TfaEq%2FaJEp19DvFxOZgLrtADi7%2BI5Fg5%2BjvMr0DqMrUsHf8%2FwC%2FTHc6PtuZDxiGvW%2FXPztR6c8IblG7gjfY3oHM%2FzNt3vHc%2FeBLc%2FWaK45hzmh3XIqGpYtE804XQoYeGwkMjJ706WRkE%2FPVNFwQ%2FaEq8APbp2VHbdINwSsKyQQgyNtmJnUnns4637UWoc2EO6lRPl%2B8bNiShUmZTBuNIXSyRB0RIVDhi3lV3sskJhGSwyFr5vF%2FlOr9LVYJSK4nUMzlV3khdn6Z9pinytteGikRvvJe2H8B0avzZLKftZEqlBE1znIEisPMgaklkQzg6mrwzQxoshONRWHvrbews%2BGjDl0%2FHLouXPFpGWl6bGgN%2BlINO7OzGLMIMz9kojUKr7HmITEfhPBfH1%2BxWNtTW3LUy9WFt%2F3UPVCigj476gbbjdYpoPA786DWeH6AHZQ3pIwXBkQ27OqiURlCPfCP%2BquCqgKBY6MU8EAffKFR8S%2Bjh%2Fg4xG06rGoBnwEn76PSb6F1LarDOqt7dUWvQR9FOb3zHTZPOiieGfJZiRG9q5s%2FfY9QGH5CThLTU3iGpdNiUZEzhUFQHE35nGjwQoml%2Fh%2FBG9oSHhgw%2BU6uxefcVYOVaEgdTlTLQtcLCb6cSeTRMX%2FOxwfCajLdZ8ZamPDRbmcC6BaL9H3qLnkeW4H6QiwUKRRrbh2T1apaUw%2B6CfH8bt8gBdfz%2B3bjgEoQUg%2Bk0EuEhA5q5ClmzaU%2B8c8K30CswquzzzgY6mAHRlHxdDMCSUhwg6RvLYh5V9YBUVWH%2BaBbghvKhmDxEn5pMYvZtrJ%2Bf7IpzwmYggFt6zWLyUCwthBmHG6bkijQsqn4SwALqwX8GH3itg40r9gAC0RVCqFKyFLXkzdfUI46jBizkeABpeaxzf4%2FOQvdrQv2QvZ%2BJ8beKVvg65j7PQDpOVo%2BN2fIvrm6duXDC%2FOL3ouWcOxLqdQ%3D%3D&amp;Expires=1776091291\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>In nearly all observed cases, the end goal is credential harvesting. Victims are lured into clicking fake billing alerts, fraudulent support numbers, or deceptive account warnings. <\/p>\n<p>Once a user hands over login credentials, attackers gain an entry point that can lead to unauthorized access, account takeovers, and deeper network compromise.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/8e6e0e54-cec0-4b3c-b33c-e79af01cbc0f\/Hackers-Abuse-GitHub-and-Jira-Notifications-to-Deliver-Phishing-Through-Trusted-SaaS-Channels.pdf?AWSAccessKeyId=ASIA2F3EMEYEU4UJ73NP&amp;Signature=FczBxoLGd8hDvOJMzCK%2BVthsjQM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEK7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCSca9owkx42QL6PAh5m%2BTMRxJobbK9SWdemA%2Fh1%2BDH%2BwIgO8%2F1HGBTK8nt%2BfIH8g9ARtpW9NJUUp2m4rw9JqBUvIEq8wQIdxABGgw2OTk3NTMzMDk3MDUiDIRSMOrPTFzfkWEF3CrQBJR0TmrMHRmBAwCvkh5EWzCCE94DFobUSADRIZX%2FxCK2TfaEq%2FaJEp19DvFxOZgLrtADi7%2BI5Fg5%2BjvMr0DqMrUsHf8%2FwC%2FTHc6PtuZDxiGvW%2FXPztR6c8IblG7gjfY3oHM%2FzNt3vHc%2FeBLc%2FWaK45hzmh3XIqGpYtE804XQoYeGwkMjJ706WRkE%2FPVNFwQ%2FaEq8APbp2VHbdINwSsKyQQgyNtmJnUnns4637UWoc2EO6lRPl%2B8bNiShUmZTBuNIXSyRB0RIVDhi3lV3sskJhGSwyFr5vF%2FlOr9LVYJSK4nUMzlV3khdn6Z9pinytteGikRvvJe2H8B0avzZLKftZEqlBE1znIEisPMgaklkQzg6mrwzQxoshONRWHvrbews%2BGjDl0%2FHLouXPFpGWl6bGgN%2BlINO7OzGLMIMz9kojUKr7HmITEfhPBfH1%2BxWNtTW3LUy9WFt%2F3UPVCigj476gbbjdYpoPA786DWeH6AHZQ3pIwXBkQ27OqiURlCPfCP%2BquCqgKBY6MU8EAffKFR8S%2Bjh%2Fg4xG06rGoBnwEn76PSb6F1LarDOqt7dUWvQR9FOb3zHTZPOiieGfJZiRG9q5s%2FfY9QGH5CThLTU3iGpdNiUZEzhUFQHE35nGjwQoml%2Fh%2FBG9oSHhgw%2BU6uxefcVYOVaEgdTlTLQtcLCb6cSeTRMX%2FOxwfCajLdZ8ZamPDRbmcC6BaL9H3qLnkeW4H6QiwUKRRrbh2T1apaUw%2B6CfH8bt8gBdfz%2B3bjgEoQUg%2Bk0EuEhA5q5ClmzaU%2B8c8K30CswquzzzgY6mAHRlHxdDMCSUhwg6RvLYh5V9YBUVWH%2BaBbghvKhmDxEn5pMYvZtrJ%2Bf7IpzwmYggFt6zWLyUCwthBmHG6bkijQsqn4SwALqwX8GH3itg40r9gAC0RVCqFKyFLXkzdfUI46jBizkeABpeaxzf4%2FOQvdrQv2QvZ%2BJ8beKVvg65j7PQDpOVo%2BN2fIvrm6duXDC%2FOL3ouWcOxLqdQ%3D%3D&amp;Expires=1776091291\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 class=\"wp-block-heading\" id=\"how-the-attack-works-github-and-jira-notification\"><strong>How the Attack Works: GitHub and Jira Notification Pipelines<\/strong><\/h2>\n<p>On GitHub, the attack begins with creating a repository. The attacker then pushes a commit with message fields loaded with social engineering content. GitHub\u2019s commit interface has two text areas: a short mandatory summary line and a longer optional description. <\/p>\n<p>The attacker places an urgent-sounding hook \u2014 such as a fake invoice or billing alert \u2014 in the summary, and fills the extended description with the full scam message, including fake phone numbers or fraudulent links. <\/p>\n<p>When the commit is submitted, GitHub automatically notifies all collaborators via email, with the full message embedded in the notification body. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhbRdDUwnrUsbvd1DMHPY8ftHJbolK69JOUkgeqXRO0QxNtpdSGjZVsV49FcRIon0CubJs4KGnxcW8b83Hj82pVpPnNJ6QnICR1NcuGG4-4fXPm_QwOprnkW_wAOq7eD6oL3VVvnsQodltdV3HvL5yOLggfkZJ91Jdcr-HhF7UL9C58DocmipWmJVKymz8\/s16000\/Email%2520header%2520%28Source%2520-%2520Cisco%2520Talos%29.webp?ssl=1\" alt=\"Email header (Source - Cisco Talos)\"><figcaption class=\"wp-element-caption\">Email header (Source \u2013 Cisco Talos)<\/figcaption><\/figure>\n<\/div>\n<p>The resulting email appears as a standard GitHub notification. The raw email headers in\u00a0confirm the sending server as \u201cout-28.smtp.github.com\u201d \u2014 a legitimate GitHub mail server with IP \u201c192.30.252.211.\u201d <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjv-6Oley7nwandVFDWBUduF4PhBWjRejPBcu_sV7S2olMCV27vsZXfaaoOkGfdyfVcC2IYca5-XqWWFc8kg_c-vKGPtABt5F23BbFZWrHhuATJIo0QwABZcm2y7TjXh9jmrjXcbLX9_6pdfWB23hAqtmRzjQsoyGvjYcWJagKGzNJVoJJAO8yZvdF6a2Y\/s16000\/The%2520body%2520of%2520the%2520message%2520%28Source%2520-%2520Cisco%2520Talos%29.webp?ssl=1\" alt=\"The body of the message (Source - Cisco Talos)\"><figcaption class=\"wp-element-caption\">The body of the message (Source \u2013 Cisco Talos)<\/figcaption><\/figure>\n<\/div>\n<p>The DKIM signature carries \u201cd=github.com\u201d and passes all checks without raising any security flag.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiXiuxDkZEsiOPgTkK5TGeUiSNZUdzoJwiYW0Lvh35DoJnsnw3lpP9vJaX8JVAL9b0ftpMWMj6MQw1LeLil_UFQVvBfdKmFnMYaHrtW3b-qX1kRMYbTJHT4lTYQ38gfj1rL7rSNttZ1jnhwsZGiNrJLXpE7ERE-aQpYOFvKcQyytM2xjcIPKBBQDqNB_ys\/s16000\/Raw%2520headers%2520%28Source%2520-%2520Cisco%2520Talos%29.webp?ssl=1\" alt=\"Raw headers (Source - Cisco Talos)\"><figcaption class=\"wp-element-caption\">Raw headers (Source \u2013 Cisco Talos)<\/figcaption><\/figure>\n<\/div>\n<p>The Jira approach uses a different mechanism. Attackers create a Jira <a href=\"https:\/\/cybersecuritynews.com\/dell-wyse-management-vulnerabilities\/\" id=\"145675\" target=\"_blank\" rel=\"noreferrer noopener\">Service Management<\/a> project, setting a fake name \u2014 such as \u201cArgenta\u201d \u2014 and embedding their phishing message inside the \u201cWelcome Message\u201d or \u201cProject Description\u201d field. <\/p>\n<p>Using the \u201cInvite Customers\u201d feature, they submit the target\u2019s email address. Atlassian\u2019s backend then generates an automated invite email, wrapping the attacker\u2019s content inside its own signed and branded template. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhiOuHmFTysmcQcHpHZzanKuuLInkzRTk9zWuPKKpBOzi3IEigM-7ySWAmS0PQQ4D-83GAJJgPORCO2XTADn0hEuzqORRWuCYwj2wKo9I4jf_RUbMAItFKajR0NMg-_m39W_aSuXfa55QqcETmc4VO3cEc7rc3XE050L8E2XtwYY9RjAtDRNbMd0nxVs1Y\/s16000\/The%2520body%2520of%2520the%2520message%2520and%2520the%2520footer%2520branding%2520%28Source%2520-%2520Cisco%2520Talos%29.webp?ssl=1\" alt=\"The body of the message and the footer branding (Source - Cisco Talos)\"><figcaption class=\"wp-element-caption\">The body of the message and the footer branding (Source \u2013 Cisco Talos)<\/figcaption><\/figure>\n<\/div>\n<p>The email arrives looking exactly like an official Jira system notification, complete with Atlassian\u2019s branding footer.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/8e6e0e54-cec0-4b3c-b33c-e79af01cbc0f\/Hackers-Abuse-GitHub-and-Jira-Notifications-to-Deliver-Phishing-Through-Trusted-SaaS-Channels.pdf?AWSAccessKeyId=ASIA2F3EMEYEU4UJ73NP&amp;Signature=FczBxoLGd8hDvOJMzCK%2BVthsjQM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEK7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCSca9owkx42QL6PAh5m%2BTMRxJobbK9SWdemA%2Fh1%2BDH%2BwIgO8%2F1HGBTK8nt%2BfIH8g9ARtpW9NJUUp2m4rw9JqBUvIEq8wQIdxABGgw2OTk3NTMzMDk3MDUiDIRSMOrPTFzfkWEF3CrQBJR0TmrMHRmBAwCvkh5EWzCCE94DFobUSADRIZX%2FxCK2TfaEq%2FaJEp19DvFxOZgLrtADi7%2BI5Fg5%2BjvMr0DqMrUsHf8%2FwC%2FTHc6PtuZDxiGvW%2FXPztR6c8IblG7gjfY3oHM%2FzNt3vHc%2FeBLc%2FWaK45hzmh3XIqGpYtE804XQoYeGwkMjJ706WRkE%2FPVNFwQ%2FaEq8APbp2VHbdINwSsKyQQgyNtmJnUnns4637UWoc2EO6lRPl%2B8bNiShUmZTBuNIXSyRB0RIVDhi3lV3sskJhGSwyFr5vF%2FlOr9LVYJSK4nUMzlV3khdn6Z9pinytteGikRvvJe2H8B0avzZLKftZEqlBE1znIEisPMgaklkQzg6mrwzQxoshONRWHvrbews%2BGjDl0%2FHLouXPFpGWl6bGgN%2BlINO7OzGLMIMz9kojUKr7HmITEfhPBfH1%2BxWNtTW3LUy9WFt%2F3UPVCigj476gbbjdYpoPA786DWeH6AHZQ3pIwXBkQ27OqiURlCPfCP%2BquCqgKBY6MU8EAffKFR8S%2Bjh%2Fg4xG06rGoBnwEn76PSb6F1LarDOqt7dUWvQR9FOb3zHTZPOiieGfJZiRG9q5s%2FfY9QGH5CThLTU3iGpdNiUZEzhUFQHE35nGjwQoml%2Fh%2FBG9oSHhgw%2BU6uxefcVYOVaEgdTlTLQtcLCb6cSeTRMX%2FOxwfCajLdZ8ZamPDRbmcC6BaL9H3qLnkeW4H6QiwUKRRrbh2T1apaUw%2B6CfH8bt8gBdfz%2B3bjgEoQUg%2Bk0EuEhA5q5ClmzaU%2B8c8K30CswquzzzgY6mAHRlHxdDMCSUhwg6RvLYh5V9YBUVWH%2BaBbghvKhmDxEn5pMYvZtrJ%2Bf7IpzwmYggFt6zWLyUCwthBmHG6bkijQsqn4SwALqwX8GH3itg40r9gAC0RVCqFKyFLXkzdfUI46jBizkeABpeaxzf4%2FOQvdrQv2QvZ%2BJ8beKVvg65j7PQDpOVo%2BN2fIvrm6duXDC%2FOL3ouWcOxLqdQ%3D%3D&amp;Expires=1776091291\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Cisco Talos recommends that organizations shift away from blindly trusting SaaS platform emails. <\/p>\n<p>Security teams should integrate GitHub and Atlassian API <a href=\"https:\/\/cybersecuritynews.com\/copilot-vulnerability-breaks-audit-logs\/\" id=\"122380\" target=\"_blank\" rel=\"noreferrer noopener\">audit logs<\/a> into a SIEM or SOAR system to flag unusual activity \u2014 such as mass user invitations or project creation from unfamiliar locations \u2014 before any phishing email is sent. <\/p>\n<p>Any notification carrying financial or urgency-driven content from platforms like GitHub or Jira should be flagged for review, as that content conflicts with those tools\u2019 intended purpose. <\/p>\n<p>For sensitive interactions, users should navigate directly to the official platform portal rather than clicking notification links. <\/p>\n<p>Organizations are also encouraged to automate takedown reports to platform Trust and Safety teams to raise the operational cost for attackers.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hackers-abuse-github-and-jira-notifications\/\">Hackers Abuse GitHub and Jira Notifications to Deliver Phishing Through Trusted SaaS Channels<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hackers-abuse-github-and-jira-notifications\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Abuse GitHub and Jira Notifications to Deliver Phishing Through Trusted SaaS Channels Cybercriminals are now weaponizing the very tools that developers and IT teams trust the most. By abusing the automated notification features built into GitHub and Jira, threat actors are delivering convincing phishing emails that originate directly from those platforms\u2019 own servers. What [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-12093","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12093"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12093"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12093\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12093"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12093"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12093"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}