Sign in

GitHub Security Lab

@securitylab.github.com
512 followers 1 following 121 posts

Securing open source software, together

PostsRepliesMedia
GitHub Security Lab @securitylab.github.com · 24/06/2026
What happens when you hand an AI agent its own tools, memory, and a path to production? Your job is to find the cracks before an attacker does. Play now: gh.io/scg Free. Open source. Get started in 2 minutes right from your browser.
000
GitHub Security Lab @securitylab.github.com · 30/05/2026
Attending AI DevCon? Join Joseph Katsioloudes and discover practical ways to use AI for security through 12 GitHub Copilot demos from secure coding, to informed supply chain decisions, and secure SDLC. 📅 June 1, 10:00 AM BST 📍 London, UK & Virtual 👉 tessl.io/speaker/jose...
000
GitHub Security Lab @securitylab.github.com · 27/05/2026
Proof of Concept for GHSL-2026-140 (CVE-2026-48095) in 7-Zip <= 26.00. A crafted archive shrinks a 256 MB buffer into 1 byte, overwrites a function pointer with file content, and redirects execution. Full weaponization needs an ASLR bypass. Fixed in 26.01. securitylab.github.com/advisories/G...
002
GitHub Security Lab @securitylab.github.com · 30/12/2025
Learn why some vulnerabilities resist to fuzzing and persist in long-enrolled OSS-Fuzz projects, and how you can find them! github.blog/security/vul...
110
GitHub Security Lab @securitylab.github.com · 19/11/2025
Attending AI Native DevCon? Join @jkcso.bsky.social and discover practical ways to use AI for security through 14 live GitHub Copilot demos from secure coding, to supply chain decisions, to MCP servers. 📅 November 19, 11:40 AM EST 📍 Industry City, Kings County, NY + online 👉 ainativedev.io/devcon
Flyer of the conference session. Title: Code Security Reinvented: Navigating the era of AI. Track: TOOLS IN ACTION. Speaker: Jospeh Katsioloudes, Cyber Security Specialist at GitHub.
000
GitHub Security Lab @securitylab.github.com · 13/11/2025
Join us at @nerdearla.bsky.social to discover how GitHub secures the open source software we rely on. From security research and education to free tools and programs that have strengthened the security of hundreds of projects. 📅 November 14, 11 AM CET 📍 LaNaveMadrid + free streaming 👉 nerdearla.es
001
GitHub Security Lab @securitylab.github.com · 13/10/2025
Are you in Warsaw for The Hack Summit Warsaw? Join Sylwia Budzynska for an introductory talk about security research, static analysis, and CodeQL: "From One Bug to Hundreds: Scaling Vulnerability Research with CodeQL" 📆 October 14, 11:20 CEST Track: Security in Software Development & DevSecOps
Flyer from the conference The Hack Summit announcing a presentation: 
Sylwia Budzynska, GitHub Security Researcher
From One Bug to Hundreds: Scaling Vulnerability Research with CodeQL
000
GitHub Security Lab @securitylab.github.com · 08/08/2025
Join Madison Oliver at DEF CON as she joins a panel on modernizing the CVE Program to meet the demands of AI-scale discovery, real-time coordination, and global software supply chains. 🗓️ Saturday, August 9 | ⏰ 12:30 PM 📍 Policy Stage | Room 234
000
GitHub Security Lab @securitylab.github.com · 09/07/2025
Curious how GitHub helps secure the open source software the world runs on? Join us tomorrow at WeAreDevelopers World Congress 2025 and see it in action. 🕚 July 10, 16:10 CET 📍 Stage 11
000
GitHub Security Lab @securitylab.github.com · 21/05/2025
🚀 Want to secure your code like a pro? Join us virtually to explore how developers can use #AI and #GitHubCopilot to build secure software—faster and smarter! 🕚 May 22, 10am GMT 📍 Online (FREE & LIVE!) 🔗 Save your spot now and forward to your peers: developer.microsoft.com/en-us/reacto...
000
GitHub Security Lab @securitylab.github.com · 09/05/2025
Season 3 of the GitHub Secure Code Game is coming — AI enters the chat 🤖🔥 Catchup with Season 1 and 2 at gh.io/secure-code-game
0106
GitHub Security Lab @securitylab.github.com · 06/02/2025
First an important point: we only research open source code, which means that many parts of your phone (for example most of your apps) are out-of-scope for us. That said, all open source code is in-scope, including projects that aren’t hosted on GitHub.
Dialogue with an open source maintainer saying that the GitHub Security Lab reported vulnerabilities on their project while it was not even hosted on GitHub, and answer from the Security Lab thanking them for their partnership in making open source more secure.
100