Multiple campaigns are using ghost accounts to map GitHub organizations, including their repositories and members.
The post Ghost Accounts Abuse GitHub API in Mass Recon Campaign appeared first on SecurityWeek.
Multiple campaigns are using ghost accounts to map GitHub organizations, including their repositories and members.
The post Ghost Accounts Abuse GitHub API in Mass Recon Campaign appeared first on SecurityWeek.
The vulnerability has been described as a case of stored cross-site scripting (XSS) that could allow specially crafted emails to execute malicious scripts in a user’s session. It has yet to be assigned a CVE identifier.
“The
The compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. The version was
The company has temporarily disabled access to the affected accounts, a step it says it took “out of an abundance of caution” while it works with internal and external security
