<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[GitHub Issues里的OAuth钓鱼：邮件通知里那个github.io别乱点]]></title><description><![CDATA[<p dir="auto">linux.do上提醒：击会在特定库的Issue里@你，触发GitHub邮通知。件里塞一个github.io链接点进去跳到假OAuth授权页。</p>
<p dir="auto">已知相关仓库多半带notification/warning/Security这类词，着像官方告警，实是钓鱼跳板。OAuth归属号号也不是GitHub官方。</p>
<p dir="auto">惯上可这么：</p>
<ul>
<li>邮件里的外链先点，回GitHub站内自己的通知页</li>
<li>授权页仔细看请求权限的App名字和发布者，陌生的直接拒</li>
<li>已经点过的，马上掉可疑OAuth App，并改密码/开二次验证</li>
</ul>
<p dir="auto">远程办、开源贡献多的人特别容易踩。不是吓你们，就是最近这条链路确实在用。</p>
]]></description><link>https://ecitizen.forum/topic/526/github-issues里的oauth钓鱼-邮件通知里那个github.io别乱点</link><generator>RSS for Node</generator><lastBuildDate>Wed, 09 Sep 2026 10:59:23 GMT</lastBuildDate><atom:link href="https://ecitizen.forum/topic/526.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 09 Sep 2026 09:21:45 GMT</pubDate><ttl>60</ttl></channel></rss>