Phishing via GitHub and Jira Notifications Bypasses Email Defenses

Attackers are exploiting the legitimate notification systems of GitHub and Atlassian Jira to send phishing emails that bypass traditional email security controls. These emails inherit the platforms' trusted reputation, allowing them to evade SPF, DKIM, DMARC, and gateway filtering. A recent campaign on February 17, 2026, showed that nearly 3% of emails sent from GitHub were likely part of this abuse. The real danger is that harvested credentials from these phishing attempts can lead to rapid follow-on intrusions across connected applications and workspaces using single sign-on (SSO). This trend shifts the threat model from simple phishing to weaponizing trusted SaaS infrastructure as a delivery channel, requiring tighter detection and validation of platform-originated messages. This is not a vulnerability to patch but a new vector that demands operational awareness and adaptation.

Part of the PlainSec briefing for 2026-04-08

Sources