Threat actors have created ghost accounts to abuse GitHub’s API in a large-scale reconnaissance campaign, according to SecurityWeek. The attack leverages fraudulent accounts to conduct automated probing of the platform, potentially gathering information for further malicious activities.