lade...
random avatar

GitHubSecurityLab - Network

Posts Subscribe

In this blog post, we detail newly discovered authentication bypass vulnerabilities in the ruby-saml library used for single sign-on (SSO)...

https://infosec.exchange/@GitHub...

In this blog post, we detail newly discovered authentication bypass vulnerabilities in the ruby-saml library used for single sign-on (SSO) via SAML on the service provider (application) side. Users of ruby-saml should update immediately to version 1.18.0.

github.blog/security/sign-in-a

12.3.2025 21:32In this blog post, we detail newly discovered authentication bypass vulnerabilities in the ruby-saml library used for single sign-on (SSO)...
https://infosec.exchange/@GitHub...

🚀 Calling all CoderGirls in Aarhus! Join @blazingwind for a Code Night at the Microsoft office—a relaxed evening of coding,...

https://infosec.exchange/@GitHub...

🚀 Calling all CoderGirls in Aarhus! Join
@blazingwind for a Code Night at the Microsoft office—a relaxed evening of coding, collaboration, and community. Whether you’re working on a project or just want to connect with fellow developers, this is for you! 🎉

📅 Thursday, March 13, 2025
⏰ 4:30 PM – 6:30 PM CET
📍 INCUBA, Åbogade 15, Århus N

Bring your laptop, bring your ideas, and let’s code together! 💻✨

12.3.2025 14:58🚀 Calling all CoderGirls in Aarhus! Join @blazingwind for a Code Night at the Microsoft office—a relaxed evening of coding,...
https://infosec.exchange/@GitHub...

Tomorrow, we are excited to host a software security competition based on gh.io/secure-code-game 🔐 for CyberWeek 2025 at the Microsoft...

https://infosec.exchange/@GitHub...

Tomorrow, we are excited to host a software security competition based on gh.io/secure-code-game 🔐 for CyberWeek 2025 at the Microsoft Technology Center in Bellevue, WA. May the more secure win!

25.2.2025 23:46Tomorrow, we are excited to host a software security competition based on gh.io/secure-code-game 🔐 for CyberWeek 2025 at the Microsoft...
https://infosec.exchange/@GitHub...

Happy Friday folks! Here is a throwback to our 2nd most popular research post of 2024, "Gaining kernel code execution on an MTE-enabled...

https://infosec.exchange/@GitHub...

Happy Friday folks! Here is a throwback to our 2nd most popular research post of 2024, "Gaining kernel code execution on an MTE-enabled Pixel 8" by Man yue Mo github.blog/security/vulnerabi

14.2.2025 11:04Happy Friday folks! Here is a throwback to our 2nd most popular research post of 2024, "Gaining kernel code execution on an MTE-enabled...
https://infosec.exchange/@GitHub...

Keep your GitHub Actions secure! Vulnerable Workflows can expose you to secrets leaks, repository takeovers, remote code execution on your...

https://infosec.exchange/@GitHub...

Keep your GitHub Actions secure! Vulnerable Workflows can expose you to secrets leaks, repository takeovers, remote code execution on your runners ... and more. Read our series on GitHub Actions security to understand the most common vulnerability patterns, learn secure practices, and protect your Workflows with CodeQL securitylab.github.com/resourc

13.2.2025 14:16Keep your GitHub Actions secure! Vulnerable Workflows can expose you to secrets leaks, repository takeovers, remote code execution on your...
https://infosec.exchange/@GitHub...

Time flies! 4 years ago Antonio Morales published his Fuzzing101 online course. 3,000 stars and hundreds of happy learners later, Rumor has...

https://infosec.exchange/@GitHub...

Time flies! 4 years ago Antonio Morales published his Fuzzing101 online course. 3,000 stars and hundreds of happy learners later, Rumor has it that Antonio is working on some new exercises! So, catch-up now on the first 10 challenges before he drops the new ones at gh.io/fuzzing101 gh.io/fuzzing101!

12.2.2025 16:21Time flies! 4 years ago Antonio Morales published his Fuzzing101 online course. 3,000 stars and hundreds of happy learners later, Rumor has...
https://infosec.exchange/@GitHub...

The Security Lab is proud to sponsor NullCon Goa 2025! We are also funding scholarship tickets to enable and empower the next generation of...

https://infosec.exchange/@GitHub...

The Security Lab is proud to sponsor NullCon Goa 2025! We are also funding scholarship tickets to enable and empower the next generation of security researchers to attend these high-quality conference sessions and network with security professionals! Enjoy, folks!

11.2.2025 16:09The Security Lab is proud to sponsor NullCon Goa 2025! We are also funding scholarship tickets to enable and empower the next generation of...
https://infosec.exchange/@GitHub...

ICYMI Nancy Gariché published an article full of insights and practical tips for those considering starting a career in Cybersecurity:...

https://infosec.exchange/@GitHub...

ICYMI Nancy Gariché published an article full of insights and practical tips for those considering starting a career in Cybersecurity: "Cybersecurity researchers: Digital detectives in a connected world" github.blog/security/vulnerabi

10.2.2025 17:42ICYMI Nancy Gariché published an article full of insights and practical tips for those considering starting a career in Cybersecurity:...
https://infosec.exchange/@GitHub...

Hey 👋🏾 it's the weekend folks! Let's enjoy a throwback to our most popular research post of 2024, "3 ways to get Remote...

https://infosec.exchange/@GitHub...

Hey 👋🏾 it's the weekend folks! Let's enjoy a throwback to our most popular research post of 2024, "3 ways to get Remote Code Execution in Kafka UI" github.blog/security/vulnerabi by @artsploit

7.2.2025 18:52Hey 👋🏾 it's the weekend folks! Let's enjoy a throwback to our most popular research post of 2024, "3 ways to get Remote...
https://infosec.exchange/@GitHub...

We’re big believers in Linus's law: “given enough eyeballs, all bugs are shallow”. Together, we’re making open source software...

https://infosec.exchange/@GitHub...

We’re big believers in Linus's law: “given enough eyeballs, all bugs are shallow”. Together, we’re making open source software secure. en.wikipedia.org/wiki/Linus%27
-- THE END --

6.2.2025 21:46We’re big believers in Linus's law: “given enough eyeballs, all bugs are shallow”. Together, we’re making open source software...
https://infosec.exchange/@GitHub...

Our deep research work is primarily intended to inspire the community, so that we can improve open source security together. That’s why we...

https://infosec.exchange/@GitHub...

Our deep research work is primarily intended to inspire the community, so that we can improve open source security together. That’s why we publish detailed blog posts and proof-of-concept exploits. github.com/github/securitylab/

6.2.2025 21:46Our deep research work is primarily intended to inspire the community, so that we can improve open source security together. That’s why we...
https://infosec.exchange/@GitHub...

And these activities also benefit open source, because GitHub security products, including Dependabot and CodeQL, are free for open source...

https://infosec.exchange/@GitHub...

And these activities also benefit open source, because GitHub security products, including Dependabot and CodeQL, are free for open source projects!

6.2.2025 21:46And these activities also benefit open source, because GitHub security products, including Dependabot and CodeQL, are free for open source...
https://infosec.exchange/@GitHub...

Similarly, our work with CodeQL provides feedback to the code scanning team to help improve and further develop the feature so that more...

https://infosec.exchange/@GitHub...

Similarly, our work with CodeQL provides feedback to the code scanning team to help improve and further develop the feature so that more vulnerabilities are caught quickly and automatically.
docs.github.com/en/code-securi

6.2.2025 21:46Similarly, our work with CodeQL provides feedback to the code scanning team to help improve and further develop the feature so that more...
https://infosec.exchange/@GitHub...

The work that we do feeds into GitHub’s security products. For example, the advisory database is used to generate Dependabot...

https://infosec.exchange/@GitHub...

The work that we do feeds into GitHub’s security products. For example, the advisory database is used to generate Dependabot alerts.
docs.github.com/en/code-securi

6.2.2025 21:46The work that we do feeds into GitHub’s security products. For example, the advisory database is used to generate Dependabot...
https://infosec.exchange/@GitHub...

And fourth, we do deep research on critical open source projects. @mmolgtm ’s work on Arm Mail is an example of...

https://infosec.exchange/@GitHub...

And fourth, we do deep research on critical open source projects. @mmolgtm ’s work on Arm Mail is an example of this.
github.blog/security/vulnerabi

6.2.2025 21:45And fourth, we do deep research on critical open source projects. @mmolgtm ’s work on Arm Mail is an example of...
https://infosec.exchange/@GitHub...

Third, we use GitHub’s CodeQL to scan thousands of open source repositories for common security mistakes, like SQL injections or path...

https://infosec.exchange/@GitHub...

Third, we use GitHub’s CodeQL to scan thousands of open source repositories for common security mistakes, like SQL injections or path traversals.
securitylab.github.com/codeql-

6.2.2025 21:45Third, we use GitHub’s CodeQL to scan thousands of open source repositories for common security mistakes, like SQL injections or path...
https://infosec.exchange/@GitHub...

Second, we share information around secure coding practices, through blogs and video...

https://infosec.exchange/@GitHub...

Second, we share information around secure coding practices, through blogs and video content.
github.blog/developer-skills/a

6.2.2025 21:44Second, we share information around secure coding practices, through blogs and video...
https://infosec.exchange/@GitHub...

First, we run the GitHub Advisory Database, which is a comprehensive database of open source vulnerabilities.https://github.com/advisories

https://infosec.exchange/@GitHub...

First, we run the GitHub Advisory Database, which is a comprehensive database of open source vulnerabilities.
github.com/advisories

6.2.2025 21:44First, we run the GitHub Advisory Database, which is a comprehensive database of open source vulnerabilities.https://github.com/advisories
https://infosec.exchange/@GitHub...

GitHub Security Lab sits within @githubsecurity and we focus exclusively on open source security with four main priorities:

https://infosec.exchange/@GitHub...

GitHub Security Lab sits within @githubsecurity and we focus exclusively on open source security with four main priorities:

6.2.2025 21:44GitHub Security Lab sits within @githubsecurity and we focus exclusively on open source security with four main priorities:
https://infosec.exchange/@GitHub...

Open source software is the foundation of much of the world’s software. So when open source wins, we win. And that’s why @github takes...

https://infosec.exchange/@GitHub...

Open source software is the foundation of much of the world’s software. So when open source wins, we win. And that’s why @github takes its responsibility seriously, to help make open source software more secure.

6.2.2025 21:43Open source software is the foundation of much of the world’s software. So when open source wins, we win. And that’s why @github takes...
https://infosec.exchange/@GitHub...
Subscribe
To add news/posts to your profile here, you must add a link to a RSS-Feed to your webfinger. One example how you can do this is to join Fediverse City.
         
Webfan Website Badge
Nutzungsbedingungen   Datenschutzerklärung  Impressum
Webfan | @Web pages | Fediverse Members