What happened
Datadog Security Labs has identified multiple coordinated campaigns systematically harvesting data from corporate GitHub organizations, including repository structures and employee account details, via the GitHub API. Attackers are masking their activity by routing requests through so-called 'ghost' accounts — legitimate-looking profiles that have sat dormant for years — alongside hijacked OAuth tokens and personal access credentials. Separately, Krebs on Security has exposed a cybersecurity startup actively soliciting zero-day vulnerability acquisitions while being operated by two convicted felons who have previously run fake intelligence firms and an AI-powered lobbying platform under assumed identities.
Why it matters for your business
The GitHub enumeration campaigns represent a low-noise reconnaissance phase that typically precedes targeted attacks on developers, CI/CD pipelines, or source code repositories — assets that sit at the heart of most modern software businesses. Because aged accounts appear indistinguishable from legitimate users, standard rate-limiting and anomaly detection may not flag the activity. Organizations should audit third-party OAuth token grants, enforce least-privilege access on GitHub, and monitor API call patterns against their organization endpoints. The fraudulent zero-day broker surfaces a different risk: security researchers or internal staff approached with lucrative acquisition offers should verify buyer legitimacy rigorously, as engaging with such outfits could expose proprietary vulnerability research or create legal liability.
What to watch next
Regulators and GitHub itself are likely to face pressure to introduce stronger verification requirements for API access and OAuth application grants following the Datadog disclosure. On the zero-day market front, scrutiny of unregulated vulnerability brokers is expected to intensify, particularly as offensive cybersecurity tooling draws closer legislative attention in both the U.S. and EU. Businesses operating bug bounty programs or conducting independent vulnerability research should establish clear counterparty vetting procedures before any disclosure or sale.
