Sign in

Peter Stöckli

@ulldma.bsky.social
456 followers 266 following 22 posts

Security Researcher and Software Engineer at GitHub Security Lab

PostsRepliesMedia
Peter Stöckli @ulldma.bsky.social · 3h
Instructions unclear. Storing more Diesel at home.
A black shirt of the Diesel clothing brand.
000
Reposted by Peter Stöckli
GitHub Security Lab @securitylab.github.com · 24/09/2026
AI-powered fuzzing is here. GitHub Security Lab’s Fuzzing Taskflow automates harness creation, coverage improvement, crash triage, and vulnerability reporting for open source projects. Read github.blog/security/app...
github.blog
AI-powered fuzzing with the GitHub Security Lab Taskflow Agent
In this blog post, I explain how to use the new fuzzing taskflow based on the GitHub Security Lab Taskflow Agent AI framework.
021
Peter Stöckli @ulldma.bsky.social · 25/09/2026
Love the energy 😅 >Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127) labs.watchtowr.com/is-this-a-jo...
labs.watchtowr.com
Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)
Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry. We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, a...
011
Peter Stöckli @ulldma.bsky.social · 22/09/2026
fp asimd evtstrm aes pmull sha1 sha2 crc32 atomics fphp asimdhp cpuid asimdrdm jscvt fcma lrcpc dcpop sha3 sm3 sm4 asimddp sha512 sve asimdfhm dit uscat ilrcpc flagm sb dcpodp sve2 sveaes svepmull svebitp erm svesha3 svesm4 flagm2 frint svei8mm svebf16 i8m m bf16 dgh bti mte ecv afp mte3 wfxt 😲
001
Reposted by Peter Stöckli
Adrienne Fichter @adfichter.eurosky.social · 10/09/2026
Frisch verbloggt: Welche Sprachmodelle stecken hinter der neuen «KI» für das Bundesparlament? Antwort: je ein amerikanisches, chinesisches und europäisches Open Weight-Modell. techjournalismus.ch/welche-sprac...
techjournalismus.ch
Welche Sprachmodelle stecken hinter der neuen "KI" für das Bundesparlament? - techjournalismus.ch
Endlich, dachte ich letzte Woche... endlich kriegen die Bundesparlamentarier:innen in Bern eine eigene KI als neues Arbeitstool.
1163
Reposted by Peter Stöckli
The C Programming Language @c-official.bsky.social · 29/07/2026
Sorry ✋️ I don't believe in the kind of mumbo jumbo that makes it harder to write incorrect code
29418
Reposted by Peter Stöckli
Stefano Cordio @scordio.github.io · 07/05/2026
Less than a week to go! 🚀 Join me this Tuesday at PH Zürich to discover how AssertJ 4 is about breaking things (carefully) to make your testing life better. Come for the technical debt, stay for the drinks and networking! 🍻 www.jug.ch/html/events/...
jug.ch
Java User Group Switzerland: Event "What's wrong with AssertJ?! - How a decade of technical debt is addressed in version 4.0"
AssertJ has been a player in Java testing for over a decade, providing an intuitive set of strongly typed assertions designed to maximize test readability. Since the launch of version 3.0, the library...
085
Reposted by Peter Stöckli
GitHub Security Lab @securitylab.github.com · 14/04/2026
AI agents that execute commands, browse the web, and coordinate with other agents are everywhere. But how do you know they're safe? We let you find out by hacking one yourself. Free, hands-on, and you can get started in under 2 minutes! Learn more in our latest blog. github.blog/security/hac...
github.blog
Hack the AI agent: Build agentic AI security skills with the GitHub Secure Code Game
Learn to find and exploit real-world agentic AI vulnerabilities through five progressive challenges in this free, open source game that over 10,000 developers have already used to sharpen their securi...
121
Reposted by Peter Stöckli
PentesterLab @pentesterlab.com · 10/03/2026
A commit meant to "strengthen the crypto" in FreshRSS ended up removing the need for a correct password. Why? Longer SHA-256 nonce + bcrypt truncation at 72 bytes. A nice example of why secure systems are about composition, not just stronger primitives. pentesterlab.com/blog/freshrs...
pentesterlab.com
How "Strengthening Crypto" Broke Authentication: FreshRSS and bcrypt's 72-Byte Limit
As part of our CVE monitoring, we came across GHSA-pcq9-mq6m-mvmp (CVE-2025-68402), an authentication bypass in FreshRSS, a self-hosted RSS aggregator. It ...
095
Reposted by Peter Stöckli
GitHub Security Lab @securitylab.github.com · 06/03/2026
Sign in with ANY password: How we used AI to break into a popular chat application, and other high-impact vulnerabilities. Read "How to scan for vulnerabilities with GitHub Security Lab’s open source AI-powered framework" github.blog/security/how...
github.blog
How to scan for vulnerabilities with GitHub Security Lab’s open source AI-powered framework
GitHub Security Lab Taskflow Agent is very effective at finding Auth Bypasses, IDORs, Token Leaks, and other high-impact vulnerabilities.
011
Peter Stöckli @ulldma.bsky.social · 21/01/2026
Check out how my colleague Man Yue Mo and I used LLMs to triage CodeQL results. The GitHub Security Lab Taskflow Agent and the prompts we used are open source and ready to be used! github.blog/security/ai-...
Two tasks in sequential order displaying which notes are added to the general notes in each step. With the step trigger analysis the notes added are triggers, permissions and secrets among others. The second task “audit injection point” potentially adds notes such as sanitizers and checks to the notes.
020
Reposted by Peter Stöckli
Xavier Rene-Corail @xcorail.bsky.social · 21/01/2026
This is amazing. Use a SAST to detect security issues, and then triage those alerts with LLMs, to remove false positives and focus on real and exploitable issues. And of course, the framework is open source.
031
Reposted by Peter Stöckli
GitHub Security Lab @securitylab.github.com · 20/01/2026
Learn how we triage security alerts in GitHub Actions and JavaScript projects with the new GitHub Security Lab Taskflow Agent, and leverage LLM to focus on the exploitable vulnerabilities. github.blog/security/ai-...
github.blog
AI-supported vulnerability triage with the GitHub Security Lab Taskflow Agent
Learn how we are using the newly released GitHub Security Lab Taskflow Agent to triage categories of vulnerabilities.
011
Reposted by Peter Stöckli
GitHub Security Lab @securitylab.github.com · 14/01/2026
Excited to share our open source agentic framework for security research, a collaborative framework that lets the community share AI "taskflows”! Read @kevinbackhouse.bsky.social 's blog post for details and a demo. Join us in strengthening open-source security! github.blog/security/com...
github.blog
Community-powered security with AI: an open source framework for security research
Announcing GitHub Security Lab Taskflow Agent, an open source and collaborative framework for security research with AI.
012
Peter Stöckli @ulldma.bsky.social · 14/01/2026
I don't know who needs to hear this: if you're thinking about automating a trivial task for the third time: just do it now! It doesn't need to be something complicated, often a shell script is enough. $1 refers to the first argument passed to the shell script. (noted so I don't forget 😉)
010
Peter Stöckli @ulldma.bsky.social · 05/01/2026
Einstein said: “Insanity is doing the same thing over and over again and expecting different results.” It looks like Einstein never used LLMs.
240
Reposted by Peter Stöckli
GitHub Security Lab @securitylab.github.com · 23/12/2025
GitHub Security Lab discovered a critical vulnerability in WooCommerce. We’d like to thank WooCommerce/Automattic for their incredibly quick response and fix of the vulnerability. If you are using WooCommerce, please update. For more info see: developer.woocommerce.com/2025/12/22/s...
developer.woocommerce.com
Store API Vulnerability Patched in WooCommerce 8.1+ - What You Need To Know
A critical vulnerability in WooCommerce 8.1+ has been patched. We strongly recommend updating immediately.
031
Reposted by Peter Stöckli
Stefano Cordio @scordio.github.io · 13/11/2025
Hack.Commit.Push Switzerland is just one week away! 🇨🇭 This is a great opportunity to get involved in Open Source projects like @assertj.github.io, with direct guidance from the maintainers!
078
Reposted by Peter Stöckli
GitHub Security Lab @securitylab.github.com · 11/11/2025
🚀 GitHub is making Actions more secure by default We recently announced upcoming changes to the pull_request_target event and environment protection rules to make GitHub Actions more secure by default. We’ve opened a discussion to gather feedback 👇 🔗 github.com/orgs/communi...
github.com
Towards a secure by default GitHub Actions · community · Discussion #179107
Why are you starting this discussion? Product Feedback What GitHub Actions topic or product is this about? Workflow Configuration Discussion Details Today, GitHub announced upcoming changes to the ...
064
Reposted by Peter Stöckli
GitHub Security Lab @securitylab.github.com · 24/10/2025
🎉 It’s Friday at #EkoParty! Join us at the GitHub booth at 15:30 for the GitHub Quiz 🧠 Test your security knowledge, win exclusive GitHub swag, grab some stickers, and chat with our experts! 👉 gh.io/eko
gh.io
GitHub Security Lab
Securing open source software, together.
021
Reposted by Peter Stöckli
GitHub @github.com · 30/09/2025
We're taking action to make the npm supply chain stronger and harder to attack. 🛡️ Check out our plan to create a more secure future for the JavaScript community.👇 github.blog/security/supply-chain-s…
github.blog
Our plan for a more secure npm supply chain
GitHub is strengthening npm's security with stricter authentication, granular tokens, and enhanced trusted publishing.
12910
Reposted by Peter Stöckli
GitHub Security Lab @securitylab.github.com · 23/09/2025
Recent account takeovers and attacks on package registries are a wake-up call: it's time to raise the bar on authentication and secure publishing practices. Find out what npm is doing—and what steps you can take—to help secure the open source supply chain: github.blog/security/sup...
github.blog
Our plan for a more secure npm supply chain
GitHub is strengthening npm's security with stricter authentication, granular tokens, and enhanced trusted publishing.
133
Reposted by Peter Stöckli
halvarflake.bsky.social @halvarflake.bsky.social · 10/09/2025
I have often stated that well-implemented memory tagging will be a game changer for memory corruptions. And it seems that with the next iPhone it's finally here: security.apple.com/blog/memory-...
security.apple.com
Blog - Memory Integrity Enforcement: A complete vision for memory safety in Apple devices - Apple Security Research
Memory Integrity Enforcement (MIE) is the culmination of an unprecedented design and engineering effort spanning half a decade that combines the unique strengths of Apple silicon hardware with our adv...
45617
Reposted by Peter Stöckli
GitHub Security Lab @securitylab.github.com · 25/08/2025
What if attackers could hijack your coding agent through a simple GitHub issue? Prompt injections are a real and growing threat for VS Code Copilot Agent. Learn how these attacks work and how you can defend your environment. Read the full research: github.blog/security/vul...
github.blog
Safeguarding VS Code against prompt injections
See how to reduce the risks of an indirect prompt injection, such as the exposure of confidential files or the execution of code without the user's consent.
052
Reposted by Peter Stöckli
joern @jrn.bsky.social · 19/08/2025
Today I have a more serious topic than usual, please consider reposting for reach: My wife and I are urgently looking for a specialist in neuropediatrics or a similar field for our autistic child with a diagnosed, but not further specified, movement disorder [1/4]
1422
Reposted by Peter Stöckli
GitHub Security Lab @securitylab.github.com · 11/08/2025
🚀 GitHub is on a mission to supercharge open-source security! We've partnered with 71 key open-source projects, giving them tools, funding, and playbooks to boost security. 🔐 Want your project to be part of this effort? Now’s the time to get involved! 💪 🔗 Find out more: github.blog/open-source/...
github.blog
Securing the supply chain at scale: Starting with 71 important open source projects
Learn how the GitHub Secure Open Source Fund helped 71 open source projects significantly improve their security posture.
031
Reposted by Peter Stöckli
Ulrike Franke @rikefranke.eu · 11/08/2025
Never change, Switzerland, never change. 😂 www.nzz.ch/meinung/schw...
Translation: On November 9, 1989, the Berlin Wall fell, triggering a domino effect of world-historical proportions. The path to German unity was suddenly clear, and the Soviet empire collapsed. The following day, the Swiss Foreign Ministry was bombarded with inquiries as to how the Federal Council assessed the caesura in Berlin. The FDFA then issued a communiqué: "It is impossible for Federal Councillor Felber to comment on all political events to journalists. After all, something important happens almost every day."
913420
Reposted by Peter Stöckli
Troy Hunt @troyhunt.com · 27/05/2025
I'm coming to Switzerland! Join me at the Microsoft Azure Zürich User Group in only a few weeks from now: www.meetup.com/de-DE/micros...
meetup.com
[In Person] Troy Hunt Have I Been Pwned Alpine Grand Tour Zürich , Di., 17. Juni 2025, 18:00 | Meetup
**IN-PERSON** Troy Hunt meetup at **Kraftwerk in Zurich** This meetup is a collaboration between several Swiss User Groups: [Azure Zurich User Group ](https://www.azurezur
1178
Reposted by Peter Stöckli
GitHub Security Lab @securitylab.github.com · 23/05/2025
Our team member Man Yue Mo is back, showing a new way to bypass MTE protection on Android phones with CVE-2025-0072. github.blog/security/vul...
github.blog
Bypassing MTE with CVE-2025-0072
See how a vulnerability in the Arm Mali GPU can be exploited to gain kernel code execution even when Memory Tagging Extension (MTE) is enabled.
063
Reposted by Peter Stöckli
Gynvael Coldwind @gynvael.bsky.social · 26/03/2025
Next Monday I'm doing a 2h webinar on files as seen through the eyes of a cybersecurity researcher. This will cover useful stuff for programmers, more junior pentesters, and other tech enthusiasts who enjoy knowing how stuff works on a computer :) hexarcana.ch/lp/files/?ut...
hexarcana.ch
Files through the eyes of a hacker
231
Peter Stöckli @ulldma.bsky.social · 13/03/2025
In this demonstration I show the impact of CVE-2025-25291/CVE-2025-25292, an authentication bypass in ruby-saml used by high profile OSS projects such as GitLab. My team coordinated with both the ruby-saml maintainer and GitLab to get this vulnerability fixed and patches are available at gh.io/glfx
1223
Peter Stöckli @ulldma.bsky.social · 12/03/2025
If you're using ruby-saml or omniauth-saml for SAML authentication make sure to update these libraries as fast as possible! Fixes for two critical authentication bypass vulnerabilities were published today (CVE-2025-25291 + CVE-2025-25292). github.blog/security/sig...
github.blog
Sign in as anyone: Bypassing SAML SSO authentication with parser differentials
Critical authentication bypass vulnerabilities were discovered in ruby-saml up to version 1.17.0. See how they were uncovered.
11110
Reposted by Peter Stöckli
GitHub Security Lab @securitylab.github.com · 12/03/2025
In this blog post, we detail newly discovered authentication bypass vulnerabilities in the ruby-saml library used for single sign-on (SSO) via SAML on the service provider (application) side. github.blog/security/sig...
github.blog
Sign in as anyone: Bypassing SAML SSO authentication with parser differentials
Critical authentication bypass vulnerabilities were discovered in ruby-saml up to version 1.17.0. See how they were uncovered.
076
Reposted by Peter Stöckli
GitHub Security Lab @securitylab.github.com · 06/02/2025
Hello from the GitHub Security Lab! We are a team of security experts who cultivate a collaborative community where developers and security professionals come together to secure open source software.
2105
Reposted by Peter Stöckli
Michael Stepankin @artsploit.com · 22/01/2025
Last year, I committed to uncovering critical vulnerabilities in Maven repositories. Now it’s time to share the findings: RCE in Sonatype Nexus, Cache Poisoning in JFrog Artifactory, and more! github.blog/security/vul...
12916
Reposted by Peter Stöckli
Max Hils @hi.ls · 12/01/2025
mitmproxy 11.1 is out! 🥳 We now support *Local Capture Mode* on Windows, macOS, and - new - Linux! This allows users to intercept local applications even if they don't have proxy settings. More details are at mitmproxy.org/posts/local-.... Super proud of this team effort. 😃
mitmproxy.org
Intercepting Linux Applications
27522
Reposted by Peter Stöckli
Sylwia Budzynska @blazingwind.bsky.social · 11/12/2024
🚀 CodeQL zero to hero part 4: Gradio case study is out! This time we dive into how I wrote CodeQL to support the @hf.co's Gradio framework, scaled the research to a thousand repositories on GitHub, and found 11 vulnerabilities. gh.io/codeql-part-4
gh.io
CodeQL zero to hero part 4: Gradio framework case study
Learn how I discovered 11 new vulnerabilities by writing CodeQL models for Gradio framework and how you can do it, too.
041
Reposted by Peter Stöckli
Luke Jahnke @nastystereo.com · 10/12/2024
My latest blog post is live! Check your Ruby on Rails applications for the use of params[:_json] nastystereo.com/security/rai...
13314
Reposted by Peter Stöckli
Luke Jahnke @nastystereo.com · 27/11/2024
My latest blog post is live! nastystereo.com/security/cro... Read how to send a cross-site POST without including a Content-Type header (without CORS). It even works with navigator.sendBeacon
37829
Reposted by Peter Stöckli
ϻг_ϻε @steven.srcincite.io · 26/11/2024
I just wrote a new blog post! This is how I (ab)used a jailed file write bug in Tomcat/Spring. Enjoy! Remote Code Execution with Spring Properties :: srcincite.io/blog/2024/11...
srcincite.io
Remote Code Execution with Spring Properties
Recently a past student came to me with a very interesting unauthenticated vulnerability in a Spring application that they were having a hard time exploiting...
17636
Reposted by Peter Stöckli
Luke Jahnke @nastystereo.com · 25/11/2024
I just published a new blog post sharing an improved Deserialization Gadget Chain for Ruby! It builds on the work of others, including Leonardo Giovanni, @ulldma.bsky.social and @vakzz.bsky.social nastystereo.com/security/rub...
0155
Reposted by Peter Stöckli
Peter Stöckli @ulldma.bsky.social · 24/06/2024
If you're interested in the inner workings of unsafe deserialization in Ruby I got you covered with a blog post that explains in detail how a concrete gadget chain works: github.blog/2024-06-20-e... Including proof of concept exploits that work up to Ruby 3.3 for Oj (JSON), Ox (XML) and more.
github.blog
Execute commands by sending JSON? Learn how unsafe deserialization vulnerabilities work in Ruby projects
Can an attacker execute arbitrary commands on a remote server just by sending JSON? Yes, if the running code contains unsafe deserialization vulnerabilities. But how is that possible? In this blog pos...
051
Peter Stöckli @ulldma.bsky.social · 24/06/2024
If you're interested in the inner workings of unsafe deserialization in Ruby I got you covered with a blog post that explains in detail how a concrete gadget chain works: github.blog/2024-06-20-e... Including proof of concept exploits that work up to Ruby 3.3 for Oj (JSON), Ox (XML) and more.
github.blog
Execute commands by sending JSON? Learn how unsafe deserialization vulnerabilities work in Ruby projects
Can an attacker execute arbitrary commands on a remote server just by sending JSON? Yes, if the running code contains unsafe deserialization vulnerabilities. But how is that possible? In this blog pos...
051
Reposted by Peter Stöckli
tomchop @tomchop.me · 19/10/2023
The talk I have at @hack_lu about Yeti and our vision of the future of forensics intelligence is online! We're already getting lots of FRs, which we'll do our best to implement before our official release EOM. Hope I made @Sebdraven proud 🥹 #dfir #infosec
youtube.com
Hack.lu 2023: Yeti: Old Dog, New Tricks - Sébastien Larinier and Thomas Chopitea
054
Peter Stöckli @ulldma.bsky.social · 31/07/2023
Where I'll demonstrate some typical Ruby on Rails gotchas on a real project: github.blog/2023-07-28-closing-vuln… E.g. Why you shouldn't match strings with ^ and $ when using Regex in Ruby.
Screenshot: A JavaScript alert message is displayed to demonstrate that a cross-site scripting vulnerability exists. This alert was triggered when the user clicked on the “Proceed” button on a link provided by the attacker. Instead of the “malicious” attacker-supplied JavaScript URL, the user only sees what the attacker wants the user to see, in this case: a harmless link to securitylab.github.com.
031
Reposted by Peter Stöckli
Catalin Cimpanu @campuscodi.risky.biz · 22/06/2023
Head of cyber at the Romanian Intelligence Service: Solarwinds attack didn't impact Romania because companies didn't pay their support and were lagging behind so many versions the exploited vulnerability didn't apply
043