GitHub Security Lab's Avatar

GitHub Security Lab

@securitylab.github.com

Securing open source software, together

311 Followers  |  1 Following  |  57 Posts  |  Joined: 31.01.2025  |  1.7245

Latest posts by securitylab.github.com on Bluesky

Preview
Securing the supply chain at scale: Starting with 71 important open source projects Learn how the GitHub Secure Open Source Fund helped 71 open source projects significantly improve their security posture.

๐Ÿš€ GitHub is on a mission to supercharge open-source security! We've partnered with 71 key open-source projects, giving them tools, funding, and playbooks to boost security. ๐Ÿ”
Want your project to be part of this effort? Nowโ€™s the time to get involved! ๐Ÿ’ช
๐Ÿ”— Find out more: github.blog/open-source/...

11.08.2025 17:27 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Post image

Join Madison Oliver at DEF CON as she joins a panel on modernizing the CVE Program to meet the demands of AI-scale discovery, real-time coordination, and global software supply chains.

๐Ÿ—“๏ธ Saturday, August 9 | โฐ 12:30 PM
๐Ÿ“ Policy Stage | Room 234

08.08.2025 08:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
GitHub Security Bug Bounty Program

Here are our July bug bounty stats!
โœ…174 bounty reports submitted
๐Ÿ‘ฅ140 hackers participated in our program
๐Ÿ’ฐ Awarded $103,202 in bounties

Found a vulnerability? Submit it here: bounty.github.com.

06.08.2025 06:57 โ€” ๐Ÿ‘ 2    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
LinkedIn This link will take you to a page thatโ€™s not on LinkedIn

Are you at Security BSides Las Vegas?

Our very own Madison Oliver is joining a panel on the evolving role of the CVE Program โ€” from funding challenges to global coordination and new governance models.

โ„น๏ธ pretalx.com/security-bsi...
๐Ÿ—“๏ธ August 5 | โฐ 13:00โ€“13:45 PT

05.08.2025 07:38 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Meet our team at Black Hat USA 2025 and DEF CON!

At Black Hat, find us at booth #4824.

Whoโ€™s attending:
Xavier Renรฉ-Corail โ€“ Senior Director, GitHub Security Lab
Kevin Backhouse โ€“ Staff Manager, Security Research
Madison Oliver โ€“ Senior Manager, Security Research

Come by and say hi!

04.08.2025 21:44 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Preview
GHSL-2025-059_7: Denial of Service (DoS) because of null pointer dereference in 7-Zip - CVE-2025-53817 7-Zip supports extracting from Compounds Documents. Null pointer dereference in the Compound handler may lead to denial of service.

GHSL-2025-059_7: Denial of Service (DoS) because of null pointer dereference in 7-Zip - CVE-2025-53817 securitylab.github.com/advisories/G...

17.07.2025 15:21 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GHSL-2025-058_7: Denial of Service (DoS) because of memory corruption in 7-Zip - CVE-2025-53816 Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service.

GHSL-2025-058_7: Denial of Service (DoS) because of memory corruption in 7-Zip - CVE-2025-53816 securitylab.github.com/advisories/G...

17.07.2025 15:17 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Modeling CORS frameworks with CodeQL to find security vulnerabilities Discover how to increase the coverage of your CodeQL CORS security by modeling developer headers and frameworks.

๐Ÿง  CORS misconfigurations are sneaky. Want to catch them with static analysis?
Kevin Stubbings from GitHub Security Lab shows how to model CORS middleware in CodeQLโ€”using Goโ€™s Gin framework as a case study.
Great insights for researchers & devs:
github.blog/security/app...

10.07.2025 19:31 โ€” ๐Ÿ‘ 3    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Curious how GitHub helps secure the open source software the world runs on? Join us tomorrow at WeAreDevelopers World Congress 2025 and see it in action.

๐Ÿ•š July 10, 16:10 CET
๐Ÿ“ Stage 11

09.07.2025 13:15 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
CVE-2025-53367: An exploitable out-of-bounds write in DjVuLibre DjVuLibre has a vulnerability that could enable an attacker to gain code execution on a Linux Desktop system when the user tries to open a crafted document.

New vuln from the GitHub Security Lab ๐Ÿ”
Antonio + Kev team up to uncover CVE-2025-53367 โ€” an out-of-bounds write in DjVuLibre that could lead to code execution on Linux desktops.
Found via fuzzing.
๐Ÿง  Read the announcement: github.blog/security/vul...

04.07.2025 09:43 โ€” ๐Ÿ‘ 4    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
GitHub Security Bug Bounty Program

Here are our June bug bounty stats!
โœ… 120 bounty reports submitted
๐Ÿ‘ฅ 103 hackers participated in our program
๐Ÿ’ฐ Awarded $43,651 in bounties

Found a vulnerability? Submit it here: bounty.github.com

02.07.2025 00:18 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
GitHub Security Bug Bounty Program

Here are our May bug bounty stats!
โœ…159 bounty reports submitted
๐Ÿ‘ฅ118 hackers participated in our program
๐Ÿ’ฐ Awarded $47,551 in bounties

Found a vulnerability? Submit it here: bounty.github.com

30.06.2025 18:15 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
DNS rebinding attacks explained: The lookup is coming from inside the house! DNS rebinding attack without CORS against local network web applications. See how this can be used to exploit vulnerabilities in the real-world.

We break down DNS rebinding attacks in our latest blog post. Explore the topic further and see how it can be used to exploit vulnerabilities in the real-world. github.blog/security/app...

30.06.2025 18:09 โ€” ๐Ÿ‘ 4    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitHub Advisory Database by the numbers: Known security vulnerabilities and what you can do about them Use these insights to automate software security (where possible) to keep your projects safe.

Our Advisory Database surpassed 20,000 reviewed security advisories last year! Discover how GitHub's Advisory Database helps prioritize vulnerabilities and address what matters most in our latest blog post. github.blog/security/git...

27.06.2025 17:13 โ€” ๐Ÿ‘ 9    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Hack the model: Build AI security skills with the GitHub Secure Code Game Dive into the novel security challenges AI introduces with the open source game that over 10,000 developers have used to sharpen their skills.

Train for the future of app security! ๐Ÿ›ก๏ธ Dive into the new season of the GitHub Secure Code Game as you go face to face with the security risks introduced by artificial intelligence. ๐Ÿค–

Ready to level up your security skills? Get to playing. ๐ŸŽฎ

18.06.2025 16:01 โ€” ๐Ÿ‘ 27    ๐Ÿ” 4    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Hack the model: Build AI security skills with the GitHub Secure Code Game Dive into the novel security challenges AI introduces with the open source game that over 10,000 developers have used to sharpen their skills.

We just launched season three of the GitHub Secure Code Game, and this time weโ€™re putting you face to face with the security risks introduced by artificial intelligence. Get ready to learn by doing and have fun doing it! github.blog/security/hac...

03.06.2025 17:18 โ€” ๐Ÿ‘ 11    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Preview
Bypassing MTE with CVE-2025-0072 See how a vulnerability in the Arm Mali GPU can be exploited to gain kernel code execution even when Memory Tagging Extension (MTE) is enabled.

Our team member Man Yue Mo is back, showing a new way to bypass MTE protection on Android phones with CVE-2025-0072. github.blog/security/vul...

23.05.2025 14:52 โ€” ๐Ÿ‘ 6    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿš€ Want to secure your code like a pro? Join us virtually to explore how developers can use #AI and #GitHubCopilot to build secure softwareโ€”faster and smarter!

๐Ÿ•š May 22, 10am GMT
๐Ÿ“ Online (FREE & LIVE!)

๐Ÿ”— Save your spot now and forward to your peers: developer.microsoft.com/en-us/reacto...

21.05.2025 09:45 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Video thumbnail

This Whatโ€™s in the SOSS? podcast is a special #MaintainerMonth episode featuring GitHubโ€™s Securing Open Source Software Fundโ€”where training meets funding to help OSS projects scale security.

๐ŸŽง openssf.org/podcast/2025...

๐Ÿ‘‰ maintainermonth.github.com/security-cha...

16.05.2025 13:04 โ€” ๐Ÿ‘ 3    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Video thumbnail

Season 3 of the GitHub Secure Code Game is coming โ€” AI enters the chat ๐Ÿค–๐Ÿ”ฅ
Catchup with Season 1 and 2 at gh.io/secure-code-game

09.05.2025 16:02 โ€” ๐Ÿ‘ 11    ๐Ÿ” 6    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
GitHub Security Bug Bounty Program

Here are our April bug bounty stats!
โœ… 145 bounty reports submitted
๐Ÿ‘ฅ 117 hackers participated in our program
๐Ÿ’ฐ Awarded $36,535 in bounties

Found a vulnerability? Submit it here: bounty.github.com.

02.05.2025 17:55 โ€” ๐Ÿ‘ 4    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitHub Actions workflow security analysis with CodeQL is now generally available ยท GitHub Changelog GitHub code scanning now offers enhanced security protection for your GitHub Actions workflow files through CodeQL analysis, which is now generally available. This feature enables you to identify and ...

CodeQL analysis is now generally available for your GitHub Actions workflow files! Use automated code scanning and Copilot autofix to detect and remediate vulnerabilities in your CI/CD pipeline.
github.blog/changelog/20...

24.04.2025 17:52 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
GitHub Security Bug Bounty Program

Hello security researchers!
Sharing the GitHub March bug bounty stats!
๐Ÿ› 198 bounty reports submitted
๐Ÿ‘ฉโ€๐Ÿ’ป 135 hackers participated in our program
๐Ÿ’ฐ Awarded $62,701 in bounties

Found a vulnerability on GitHub? Submit it here: bounty.github.com

16.04.2025 00:28 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
How to request a change to a CVE record Learn how to identify which CVE Numbering Authority is responsible for the record, how to contact them, and what to include with your suggestion.

In our latest blogpost, learn how to identify which CVE Numbering Authority is responsible for the record, how to contact them, and what to include with your suggestion. github.blog/security/vul...

09.04.2025 21:20 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Are you in Athens for Devoxx Greece?
Don't miss @jkcso.bsky.social's talks on the main stage this Thursday and Friday! Discover how AI, Developer Experience (DevEx), and communities shape software security through real-world examples from securely building GitHub using GitHub ๐Ÿ”’

08.04.2025 21:56 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Thursday, April 10
- 11:00 โ€“ 11:30: "CVE Unmoored: Implications of the Removal of the Technology Requirement" by Jonathan Evans

04.04.2025 19:31 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Wednesday, April 9
- 09:00 โ€“ 09:30: "Breaking the Build: How Attackers Abuse GitHub Actions" by Jonathan Evans

04.04.2025 19:31 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Tuesday, April 8
- 16:30 โ€“ 17:00: "Exploit Maturity: Your New Best Friend in CVSS" by Shelby Cunningham

04.04.2025 19:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Tuesday, April 8
- 15:00 โ€“ 16:00: "CNA Birds of a Feather: Open Forum with Certified Naming Authorities" by David Welch & Jonathan Evans
- 16:00 โ€“ 16:30: "Managing Coordinated Disclosures: A Practical Workshop on Vulnerability Coordination" by Jeffrey Guerra & Sara Clements

04.04.2025 19:29 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Monday, April 7
- 12:30 โ€“ 13:00: "From NIST to FIRST: How GitHubโ€™s Product Security Response Organization Transitioned" by Jeffrey Guerra & Sara Clements
- 14:30 โ€“ 15:30: "Vulnerability Poker: Real or AI Fake Vulnerabilities?" by Madison Oliver & Tobias Heldt

04.04.2025 19:28 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@securitylab.github.com is following 1 prominent accounts