Tag: OAuth application

Fake “Security Alert” issues on GitHub use OAuth app to hijack accounts
News

Fake “Security Alert” issues on GitHub use OAuth app to hijack accounts

Nearly 12,000 GitHub repositories have been the victim of a large phishing effort that poses as "Security Alert" problems in an attempt to fool developers into approving a malicious OAuth application that gives attackers complete control over their accounts and code. Security Notice: Strange Attempt at Access We have identified a GitHub phishing attempt on your account that seems to be coming from a different location or device. The same phrase appears in all GitHub phishing issues, alerting users to odd activity on their account from the IP address 53.253.117.8 and Reykjavik, Iceland. The phony security notice, which informed GitHub users that their accounts had been compromised and advised them to change their passwords read more about Fake "Security Alert" issues on GitHub use...