GitHub Security Lab

399 Followers
2 Following
106 Posts

Attending AI DevCon? Join Joseph Katsioloudes and discover practical ways to use AI for security through 12 GitHub Copilot demos from secure coding, to informed supply chain decisions, and secure SDLC.

πŸ“… June 1, 10:00 AM BST
πŸ“ London, UK & Virtual
πŸ‘‰ https://tessl.io/speaker/josephkatsioloudes/

Proof of Concept for GHSL-2026-140 (CVE-2026-48095) in 7-Zip <= 26.00. A crafted archive shrinks a 256 MB buffer into 1 byte, overwrites a function pointer with file content, and redirects execution. Full weaponization needs an ASLR bypass. Fixed in 26.01. Read more at https://securitylab.github.com/advisories/GHSL-2026-140_7-Zip/

Your mother tongue is the new programing language for creating exploits.

For maintainer month, we took inspiration from #OpenClaw and built ProdBot! An intentionally vulnerable agent wired up with MCPs, skills, agentic workflows, and multi-agent capabilities. You will learn from it, while having fun!

Play now at: gh.io/secure-code-game
Learn more: https://github.blog/security/hack-the-ai-agent-build-agentic-ai-security-skills-with-the-github-secure-code-game/

Learn why some vulnerabilities resist to fuzzing and persist in long-enrolled OSS-Fuzz projects, and how you can find them!

https://github.blog/security/vulnerability-research/bugs-that-survive-the-heat-of-continuous-fuzzing/

Attending AI Native DevCon? Join @jkcso.bsky.social and discover practical ways to use AI for security through 14 live GitHub Copilot demos from secure coding, to supply chain decisions, to MCP servers.
πŸ“… November 19, 11:40 AM EST

πŸ“ Industry City, Kings County, NY + online
πŸ‘‰ ainativedev.io/devcon

Join us at @nerdearla to discover how GitHub secures the open source software we all rely on. From groundbreaking security research and education initiatives to free tools for open source and programs that have strengthened the security of hundreds of projects worldwide β€” we’re excited to share it all!

πŸ“… November 14, 11 AM CET
πŸ“ LaNaveMadrid + free online streaming
πŸ‘‰ nerdearla.es

πŸ‘‹ Hola Argentina! We’re thrilled to be at #EkoParty this week!

If you’re around, swing by the GitHub booth β€” grab some stickers, play our security games, and chat with our experts about all things open source & security.

See you there πŸ‘‰ gh.io/eko

The internet was on fire. πŸ”₯
One small library affecting billions of systems.
Log4Shell was the biggest security vulnerability of all time.

Now, Log4J maintainer, Christian Grobmeier tells us what it felt like inside the flames πŸ‘‰ https://github.blog/open-source/inside-the-breach-that-broke-the-internet-the-untold-story-of-log4shell/

Are you in Warsaw for @thehacksummit ? Join Sylwia Budzynska for an introductory talk about security research, static analysis, and CodeQL: "From One Bug to Hundreds: Scaling Vulnerability Research with CodeQL"

πŸ“† October 14, 11:20 CEST
Track: Security in Software Development & DevSecOps

The future of vulnerability disclosure needs to keep up with AI-discovered vulnerabilities.

Join Madison Oliver at DEF CON as she joins a panel on modernizing the CVE Program to meet the demands of AI-scale discovery, real-time coordination, and global software supply chains.

πŸ—“οΈ Saturday, August 9 | ⏰ 12:30 PM
πŸ“ Policy Stage | Room 234