Contact us

Threat Intelligence - Cyber Attack News — August 2026

Archived cyber attack coverage from August 2026. Stories are aggregated from publicly available security news reporting and kept here as the feed refreshes each day.

Archive — August 2026 · Supply Chain Security

← All stories

1 story from August 2026.

Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

Developer Security/Supply Chain Security

Datadog Security Labs is warning of "several overlapping campaigns" that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHubAPI. "Operators rely on automated scraping tooling with custom or legitimate-sounding user agents, leveraging GitHub 'ghost' accounts that are often years old, or compromised OAuth tokens and personal access tokens (PATs) from legitimate users," Julie Agnes Sparks, senior security engineer at Datadog, said . While the activity in most cases involves targeting public data, select instances have gone beyond public information enumeration to successfully clone private repositories. The campaign employs a mix of automated scanner tools, over 50 dormant accounts, and dozens of legitimate accounts that have had their personal access tokens (PATs) exposed unintentionally or compromised through some other method to facilitate the enumeration. What's notable about the ...