GLOBEALERT
CYBERELEVATEDJul 9 · Jul 9, 2026, 6:38 PM

Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

The Hacker News

Datadog Security Labs is warning of "several overlapping campaigns" that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API. "Operators rely on automated scraping tooling with custom or legitimate-sounding user agents, leveraging GitHub 'ghost' accounts that are often years old, or compromised OAuth tokens and personal

GlobeAlert aggregates and classifies open sources; the story above belongs to its publisher. Summaries are machine-generated from the source text.

More in Cyber