GitHub Security Lab

399 Followers
2 Following
106 Posts

Attending BSides Vilnius? Don't miss ๐Ÿ“Œ @yarlob 's session "LLM-assisted vulnerability hunting: hype vs. reality" to hear about the practical experience of using LLM for finding vulnerabilities in OSS such as Signal or 7-Zip!

๐Ÿ“… June 4, 16:45 EEST
๐Ÿ“ Vilnius, Lithuania
๐Ÿ‘‰ https://bsidesvilnius.lt/

BSides Vilnius 2026 โ€” Security Theater | Cybersecurity Conference in Lithuania

BSides Vilnius 2026 โ€” community-driven cybersecurity conference in Lithuania. Workshops, talks, and CTF on 3โ€“4 June at Kablys. Join the infosec community.

BSides Vilnius

Who's at DevTalks? Join @jkcso and discover practical ways to use AI for security through 12 GitHub Copilot demos from secure coding, to informed supply chain decisions, and secure SDLC.

๐Ÿ“… June 4, 14:00 EEST
๐Ÿ“ Bucharest, Romania
๐Ÿ‘‰ https://www.devtalks.ro/

DevTalks Romania

The largest expo conference for software developers and IT professionals in Romania, gathering over 8000 participants from all over the world.

DevTalks Romania

Attending AI DevCon? Join Joseph Katsioloudes and discover practical ways to use AI for security through 12 GitHub Copilot demos from secure coding, to informed supply chain decisions, and secure SDLC.

๐Ÿ“… June 1, 10:00 AM BST
๐Ÿ“ London, UK & Virtual
๐Ÿ‘‰ https://tessl.io/speaker/josephkatsioloudes/

Proof of Concept for GHSL-2026-140 (CVE-2026-48095) in 7-Zip <= 26.00. A crafted archive shrinks a 256 MB buffer into 1 byte, overwrites a function pointer with file content, and redirects execution. Full weaponization needs an ASLR bypass. Fixed in 26.01. Read more at https://securitylab.github.com/advisories/GHSL-2026-140_7-Zip/

Your mother tongue is the new programing language for creating exploits.

For maintainer month, we took inspiration from #OpenClaw and built ProdBot! An intentionally vulnerable agent wired up with MCPs, skills, agentic workflows, and multi-agent capabilities. You will learn from it, while having fun!

Play now at: gh.io/secure-code-game
Learn more: https://github.blog/security/hack-the-ai-agent-build-agentic-ai-security-skills-with-the-github-secure-code-game/

On 25th April at 10AM, join @blazingwindsec
for the workshop "Introduction to security research. Find a CVE with CodeQL" at the Linux Session organized by Akademickie Stowarzyszenie Informatyczne in Wroclaw, Poland!

More information on the conference's website: linuksowa.pl

Building with AI? ๐Ÿค–
Then you wonโ€™t want to miss tomorrowโ€™s @devoxxfr workshop with @xcorail and @jkcso โ€” all about how to build robust AI-powered applications.

Shall we play a Game? LLM Security in Practice
https://m.devoxx.com/events/devoxxfr2026/talks/29753/shall-we-play-a-game-llm-security-in-practice

๐Ÿ“ Paris 142
๐Ÿ—“๏ธ April 22, 10.30am CET

Devoxx Mobile Companion

Your ultimate companion for Devoxx conferences worldwide. Browse talks, speakers, schedules, and manage your personalized conference experience.

Devoxx Companion

Catch Shelby Cunningham on stage at CVE/FIRST VulnCon 2026 in Scottsdale, Arizona.

Her panel, โ€œSupply Chains and Malware Campaigns: Is CVE the Right Way to Name the Game?โ€, examines whether CVE is the right tool for tracking open-source supply chain compromises โ€” from isolated package incidents to large-scale campaigns affecting hundreds of packages.

Date: April 16, 2026 | 1:15โ€“2:15 PM MST (UTC-7)

Learn more: https://www.first.org/conference/vulncon26/program#pSupply-Chains-and-Malware-Campaigns-Is-CVE-the-Right-Way-to-Name-the-Game

Program Agenda / CVE Program & FIRST VulnCon 2026

Save the Date: CVE/FIRST VulnCon 2026 & Annual CNA Summit - Scottsdale (US), April 13โ€“16, 2026

FIRST โ€” Forum of Incident Response and Security Teams
AI agents that execute commands, browse the web, and coordinate with other agents are everywhere. But how do you know they're safe? Season 4 of Github's Secure Code Game lets you find out by hacking one yourself. Free, hands-on, and you can get started in under 2 minutes! Learn more in our latest blog. https://github.blog/security/hack-the-ai-agent-build-agentic-ai-security-skills-with-the-github-secure-code-game/
Hack the AI agent: Build agentic AI security skills with the GitHub Secure Code Game

Learn to find and exploit real-world agentic AI vulnerabilities through five progressive challenges in this free, open source game that over 10,000 developers have already used to sharpen their security skills.

The GitHub Blog

Whoโ€™s at VulnCon? Join Sophia Sanles-Luksetich and Zachary Goldman at CVE/FIRST VulnCon 2026 in Scottsdale, Arizona.

Their talk, โ€œFlipping the Criticality Funnel: A Practical Path to Real Prioritizationโ€, covers how GitHub built a unified risk-scoring model that combines CVSS, EPSS, KEV, and asset context to cut through alert noise and drive remediation where it matters most.

Date: April 15, 2026 | 11:35 AMโ€“12:05 PM MST (UTC-7)

Learn more: https://www.first.org/conference/vulncon26/program#pFlipping-the-Criticality-Funnel-A-Practical-Path-to-Real-Prioritization

Program Agenda / CVE Program & FIRST VulnCon 2026

Save the Date: CVE/FIRST VulnCon 2026 & Annual CNA Summit - Scottsdale (US), April 13โ€“16, 2026

FIRST โ€” Forum of Incident Response and Security Teams