Are you at Security BSides Las Vegas? Our very own Madison Oliver is joining a panel on the evolving role of the CVE Program — from funding challenges to global coordination and new governance models. ℹ️ https://lnkd.in/gRhsg78W 🗓️ August 5 | ⏰ 13:00–13:45 PT
About us
- Website
-
https://securitylab.github.com
External link for GitHub Security Lab
- Industry
- Software Development
Updates
-
Meet our team at Black Hat USA 2025 and DEF CON! At Black Hat, find us at booth #4824. We'll have experts there from several different GitHub teams, to show demos and help with technical questions. Or if you'd like a more in-depth discussion, we also have slots available for business meetings. Of course, we'll also have lots of Octocat stickers available! Who’s attending: Xavier René-Corail – Senior Director, GitHub Security Lab Kevin Backhouse – Staff Manager, Security Research Madison Oliver – Senior Manager, Security Research Come by and say hi — we’d love to connect!
-
GitHub Security Lab reposted this
🛸 Looking for signs of intelligent life at DEF CON? 👽 come join me, Trey Ford, Madison Oliver,and Chandan at "Disclosure Encounters of a New Kind: Building the CVE Program of the Future". We’ll talk about the future of the CVE program, how CVE labelling can evolve with emerging technologies, and how public policy can promote innovation within the CVE Program to meet growing global expectations. 📅 Saturday, Aug 9, 12:30 PM 📍 Policy Stage Policy @ DEF CON - Room 234 Come for the panel, stay for the close encounters (of the cybersecurity kind)! And reach out to me if you'll be at #DEFCON #CVE #Cybersecurity #DEFCON33
-
-
GHSL-2025-059_7: Denial of Service (DoS) because of null pointer dereference in 7-Zip - CVE-2025-53817 https://lnkd.in/gEAYU3h2
-
GHSL-2025-058_7: Denial of Service (DoS) because of memory corruption in 7-Zip - CVE-2025-53816 https://lnkd.in/gqbAH86V
-
New from the GitHub Security Lab: Misconfigured CORS can expose web applications to serious security risks—but detecting those issues across frameworks isn’t always straightforward. In this deep dive, Kevin Stubbings shows how to model CORS headers and middleware with CodeQL to uncover vulnerabilities—even in custom or third-party frameworks like Gin in Go. Whether you’re a developer or security researcher, this is a must-read on strengthening your app’s defenses. 👉 https://lnkd.in/g3DEgGhr
-
Curious how GitHub helps secure the open source software the world runs on? Join us tomorrow at WeAreDevelopers World Congress 2025 and see it in action. 🕚 July 10, 16:10 CET 📍 Stage 11
-
-
🔐 New vulnerability research from the GitHub Security Lab CVE-2025-53367 is an exploitable out-of-bounds write in DjVuLibre, a graphics library used in several document processing tools. GitHub researchers Antonio Morales and Kevin Backhouse teamed up on this one: – Antonio found the bug via fuzzing – Kev built a proof of concept exploit This vulnerability can lead to remote code execution on Linux desktops. 📖 Read the announcement: https://lnkd.in/gH9RDbMy
-
GitHub Security Lab reposted this
Think you can hack an LLM? 👾 How about fixing the code to prevent the hack in the future? 👀 Play the GitHub Secure Code Game and find out. 🎮 gh.io/secure-code-game
-
Here are our June bug bounty stats! ✅ 120 bounty reports submitted 👥 103 hackers participated in our program 💰 Awarded $43,651 in bounties Found a vulnerability? Submit it here: https://bounty.github.com