{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/identity-threats/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GitHub"],"_cs_severities":["low"],"_cs_tags":["cloud-security","saas-security","identity-threats","persistence"],"_cs_type":"advisory","_cs_vendors":["GitHub"],"content_html":"\u003cp\u003eThis threat involves the abuse of GitHub OAuth application authorization (\u003ccode\u003eoauth_authorization.create\u003c/code\u003e) to establish persistent access to an environment. Unlike GitHub App installations, user-authorized OAuth applications provide tokens that grant the application access to the user's data, including private repositories. A critical risk is that these OAuth grants persist even if the user changes their GitHub account password, as the authorization is tied to the grant rather than just the user's credentials. Attackers leverage this mechanism to maintain access to repositories, clone code, or download ZIP archives long after initial compromise. Detection of this activity requires monitoring GitHub audit logs for OAuth grant events and pivoting to subsequent repository access logs.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to clone private repositories or download source code, potentially leading to the exfiltration of sensitive intellectual property, secrets, or API keys. Because these grants persist beyond password resets, this technique provides a durable backdoor into development environments, affecting organizations relying on GitHub for code hosting and CI/CD pipelines.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDetection and response teams should implement monitoring for unauthorized OAuth application grants and maintain strict governance over third-party integrations.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement monitoring for the \u003ccode\u003eoauth_authorization.create\u003c/code\u003e action within GitHub audit logs to alert on unexpected or suspicious application grants.\u003c/li\u003e\n\u003cli\u003eEstablish an allowlist of approved internal and vendor OAuth applications and investigate any grant that does not match this list.\u003c/li\u003e\n\u003cli\u003eFor suspected unauthorized access, immediately revoke the OAuth grant, invalidate existing tokens, reset the compromised user's password, and invalidate active sessions.\u003c/li\u003e\n\u003cli\u003eReview organization-wide third-party application restrictions to limit the scope and risk of OAuth grants.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T20:15:23Z","date_published":"2026-10-01T20:15:23Z","id":"https://feed.craftedsignal.io/briefs/2026-10-github-oauth-persistence/","summary":"Attackers can achieve persistent unauthorized access to GitHub repositories by abusing OAuth application grants, which remain valid even after user password resets.","title":"GitHub OAuth Application Authorization Persistence","url":"https://feed.craftedsignal.io/briefs/2026-10-github-oauth-persistence/"}],"language":"en","title":"CraftedSignal Threat Feed - Identity-Threats","version":"https://jsonfeed.org/version/1.1"}