GBHackers News reports that widely used software-as-a-service collaboration platforms GitHub and Atlassian Jira have had their alert systems exploited to deploy phishing emails without being flagged by SPF, DKIM, and DMARC checks.Attackers have targeted GitHub's automated commit notification system to craft repositories and advance malicious commits with summary lines citing billing or account issues and extended description fields with bogus billing statements and support numbers, phishing links, and other scam content, according to Cisco Talos researchers. Pushing a commit triggers the delivery of an automated email to collaborators' inboxes that evades security filters.On the other hand, threat actors who set their sights on Jira aimed at the platform's invitation and service desk workflows, with lures inserted into the configurable fields of created Jira Service Management projects. Automated distribution of "Customer Invite" or "Service Desk" emails then results in the injection of malicious content into Atlassian's trusted templates, leading to seemingly legitimate messages.Such a threat should prompt organizations to reinforce identity checking measures and transition toward zero-trust for SaaS notifications.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds




