<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/oauth-attacks-target-microsoft-365-and-github-accounts-usdhkhonh" -->

---
title: OAuth Attacks Target Microsoft 365 and GitHub Accounts
description: Recent cyberattacks use malicious OAuth applications posing as legitimate services to target sectors like healthcare and government. These attacks notably...
canonical: https://daily.dev/posts/oauth-attacks-target-microsoft-365-and-github-accounts-usdhkhonh
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: OAuth Attacks Target Microsoft 365 and GitHub Accounts | daily.dev
og:description: Recent cyberattacks use malicious OAuth applications posing as legitimate services to target sectors like healthcare and government. These attacks notably...
og:url: https://daily.dev/posts/oauth-attacks-target-microsoft-365-and-github-accounts-usdhkhonh
og:image: https://api.daily.dev/og/posts/USDHKHOnh.png
og:image:alt: OAuth Attacks Target Microsoft 365 and GitHub Accounts
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# OAuth Attacks Target Microsoft 365 and GitHub Accounts

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

Recent cyberattacks use malicious OAuth applications posing as legitimate services to target sectors like healthcare and government. These attacks notably compromise GitHub repositories through deceptive security alerts that lead users to authorize harmful OAuth apps. Developers and organizations are at risk as attackers gain complete control over affected repositories, potentially leaking sensitive data. Vigilance and robust security practices are essential to mitigate these threats.

## Content

# OAuth Attacks on Microsoft 365 and GitHub: A Growing Cyber Threat

Recent cyberattacks are capitalizing on malicious OAuth applications disguised as legitimate services such as Adobe Acrobat and DocuSign. These malicious apps redirect users to phishing or malware distribution sites, targeting various sectors including healthcare and government. By exploiting OAuth, attackers are bypassing traditional security measures and maintaining persistent access to users' accounts.

A notable aspect of these attacks is their impact on GitHub. Over 12,000 repositories have been compromised through deceptive campaigns. These campaigns typically involve fake security alerts that prompt developers to take immediate action, such as changing their passwords or enabling two-factor authentication. However, the links provided in these alerts lead to a risky OAuth authorization page, granting full access to the attackers.

The GitHub community, including thousands of repositories, has been heavily affected. Developers are tricked into believing these alerts are genuine, as the messages appear to address security concerns. By authorizing the malicious OAuth application, attackers gain complete control over the affected repositories, potentially compromising sensitive data and leading to further exploitation.

These attacks are sophisticated and potentially linked to nation-states with North Korea being a possible culprit. They represent a significant threat to both individual developers and larger organizations. It is imperative for users to remain vigilant, scrutinize authorization requests, and adhere to robust security practices, including regular updates and two-factor authentication.

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#microsoft](https://daily.dev/tags/microsoft), [#github](https://daily.dev/tags/github), [#phishing](https://daily.dev/tags/phishing), [#oauth](https://daily.dev/tags/oauth)

[View this post on daily.dev](https://daily.dev/posts/oauth-attacks-target-microsoft-365-and-github-accounts-usdhkhonh)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"OAuth Attacks Target Microsoft 365 and GitHub Accounts","url":"https://daily.dev/posts/oauth-attacks-target-microsoft-365-and-github-accounts-usdhkhonh","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/oauth-attacks-target-microsoft-365-and-github-accounts-usdhkhonh"},"datePublished":"2025-03-17T22:00:26.637Z","dateModified":"2025-03-18T13:32:48.883Z","description":"Recent cyberattacks use malicious OAuth applications posing as legitimate services to target sectors like healthcare and government. These attacks notably...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/7575ff200e60481ee1ecdef73cfdd4a9?_a=AQAEuj9","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/7575ff200e60481ee1ecdef73cfdd4a9?_a=AQAEuj9","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/oauth-attacks-target-microsoft-365-and-github-accounts-usdhkhonh","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,microsoft,github,phishing,oauth","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"OAuth Attacks Target Microsoft 365 and GitHub Accounts"}]}
```

