GitHub Security Lab's Avatar

GitHub Security Lab

@securitylab.github.com

Securing open source software, together

421
Followers
1
Following
85
Posts
31.01.2025
Joined
Posts Following

Latest posts by GitHub Security Lab @securitylab.github.com

Preview
How to scan for vulnerabilities with GitHub Security Lab’s open source AI-powered framework GitHub Security Lab Taskflow Agent is very effective at finding Auth Bypasses, IDORs, Token Leaks, and other high-impact vulnerabilities.

Sign in with ANY password: How we used AI to break into a popular chat application, and other high-impact vulnerabilities. Read "How to scan for vulnerabilities with GitHub Security Lab’s open source AI-powered framework" github.blog/security/how...

06.03.2026 21:20 👍 1 🔁 1 💬 0 📌 0
https://bounty.github.com

Hello hackers! Here are our February bug bounty stats!

🐛 200 bounty reports submitted
👩‍💻 144 hackers participated in our program
💰 Awarded $48,589 in bounties

Found a vulnerability? Submit it here:
t.co/HG2AqybW0p

06.03.2026 19:57 👍 0 🔁 0 💬 0 📌 0

If you're at #DeveloperWeek and you care about open source security, there is a session you must attend. We have been contributing to secure open source for 6 years and @xcorail.bsky.social will share with you the lessons learned from this journey! How GitHub Secures Open Source, PRO stage, 1pm.

19.02.2026 16:55 👍 1 🔁 0 💬 0 📌 1
https://bounty.github.com

Here are our January bug bounty stats!
🐛 182 bounty reports submitted
👩‍💻 112 hackers participated in our program
💰 Awarded $76,269 in bounties
Found a vulnerability? Submit it here: t.co/HG2AqybW0p.

09.02.2026 22:52 👍 1 🔁 0 💬 0 📌 0
Preview
AI-supported vulnerability triage with the GitHub Security Lab Taskflow Agent Learn how we are using the newly released GitHub Security Lab Taskflow Agent to triage categories of vulnerabilities.

Learn how we triage security alerts in GitHub Actions and JavaScript projects with the new GitHub Security Lab Taskflow Agent, and leverage LLM to focus on the exploitable vulnerabilities. github.blog/security/ai-...

20.01.2026 22:33 👍 1 🔁 1 💬 0 📌 1
Preview
Community-powered security with AI: an open source framework for security research Announcing GitHub Security Lab Taskflow Agent, an open source and collaborative framework for security research with AI.

Excited to share our open source agentic framework for security research, a collaborative framework that lets the community share AI "taskflows”! Read @kevinbackhouse.bsky.social 's blog post for details and a demo. Join us in strengthening open-source security! github.blog/security/com...

14.01.2026 23:24 👍 1 🔁 2 💬 0 📌 0
GitHub Security Bug Bounty Program

We wrapped up 2025 on a high note—here are the bug bounty stats for December!
✅ 151 bounty reports submitted
👥110 hackers participated in our program
💰Awarded $48,367 in bounties

Found a vulnerability? Submit it here: bounty.github.com.

06.01.2026 21:41 👍 3 🔁 0 💬 0 📌 0
Preview
Resources Securing open source software, together.

Want to learn more about fuzzing?
You’ll find a dedicated section at the bottom of our website’s resources page at securitylab.github.com/open-source/

30.12.2025 09:00 👍 2 🔁 0 💬 0 📌 0
Post image

Learn why some vulnerabilities resist to fuzzing and persist in long-enrolled OSS-Fuzz projects, and how you can find them!

github.blog/security/vul...

30.12.2025 08:59 👍 1 🔁 0 💬 1 📌 0
Preview
Resources Securing open source software, together.

In just 17 minutes, @yarlob.bsky.social shares his knowledge about securing GitHub Actions, drawing from hands-on experience uncovering hundreds of real-world vulnerabilities.

The talk wraps up with FREE tools to automate GitHub Actions security you can start using TODAY.

gh.io/secure-githu...

23.12.2025 19:43 👍 0 🔁 0 💬 0 📌 0
Preview
Store API Vulnerability Patched in WooCommerce 8.1+ - What You Need To Know A critical vulnerability in WooCommerce 8.1+ has been patched. We strongly recommend updating immediately.

GitHub Security Lab discovered a critical vulnerability in WooCommerce. We’d like to thank WooCommerce/Automattic for their incredibly quick response and fix of the vulnerability.

If you are using WooCommerce, please update. For more info see:
developer.woocommerce.com/2025/12/22/s...

23.12.2025 16:52 👍 3 🔁 1 💬 0 📌 0
https://bounty.github.com

Hello Hackers! Here are our November bug bounty stats!
🐛146 bounty reports submitted
👩‍💻102 hackers participated in our program
💰Awarded $93,068 in bounties
Found a vulnerability? Submit it here: bounty.github.com

01.12.2025 23:52 👍 0 🔁 0 💬 0 📌 0
Flyer of the conference session. Title: Code Security Reinvented: Navigating the era of AI. Track: TOOLS IN ACTION. Speaker: Jospeh Katsioloudes, Cyber Security Specialist at GitHub.

Flyer of the conference session. Title: Code Security Reinvented: Navigating the era of AI. Track: TOOLS IN ACTION. Speaker: Jospeh Katsioloudes, Cyber Security Specialist at GitHub.

Attending AI Native DevCon? Join @jkcso.bsky.social and discover practical ways to use AI for security through 14 live GitHub Copilot demos from secure coding, to supply chain decisions, to MCP servers.
📅 November 19, 11:40 AM EST

📍 Industry City, Kings County, NY + online
👉 ainativedev.io/devcon

19.11.2025 07:36 👍 0 🔁 0 💬 0 📌 0
Post image

Join us at @nerdearla.bsky.social to discover how GitHub secures the open source software we rely on. From security research and education to free tools and programs that have strengthened the security of hundreds of projects.

📅 November 14, 11 AM CET
📍 LaNaveMadrid + free streaming
👉 nerdearla.es

13.11.2025 09:04 👍 0 🔁 1 💬 0 📌 0
Towards a secure by default GitHub Actions · community · Discussion #179107 Why are you starting this discussion? Product Feedback What GitHub Actions topic or product is this about? Workflow Configuration Discussion Details Today, GitHub announced upcoming changes to the ...

🚀 GitHub is making Actions more secure by default

We recently announced upcoming changes to the pull_request_target event and environment protection rules to make GitHub Actions more secure by default.

We’ve opened a discussion to gather feedback 👇

🔗 github.com/orgs/communi...

11.11.2025 18:38 👍 6 🔁 4 💬 0 📌 0
GitHub Security Bug Bounty Program

Here are our October bug bounty stats!

🐛 162 bounty reports submitted
🎃 121 hackers participated in our program
💰 Awarded $78,968 in bounties

Found a vulnerability? Submit it here: bounty.github.com

04.11.2025 19:38 👍 3 🔁 0 💬 0 📌 0

Building with AI? 🤖
Then you won’t want to miss tomorrow’s #GitHubUniverse workshop with Joseph Katsioloudes and Rahul Zhade — all about how to build secure LLM-powered applications.

📍 Fort Mason Center for Arts & Culture
🗓️ Oct 29, 1:15–2:45 PM PDT

28.10.2025 19:48 👍 1 🔁 0 💬 0 📌 0
Preview
GitHub Security Lab Securing open source software, together.

🎉 It’s Friday at #EkoParty!
Join us at the GitHub booth at 15:30 for the GitHub Quiz 🧠
Test your security knowledge, win exclusive GitHub swag, grab some stickers, and chat with our experts!
👉 gh.io/eko

24.10.2025 14:09 👍 2 🔁 1 💬 0 📌 0

Aprende como usar LLMs para mejorar el proceso de fuzzing en la charla de Antonio Morales en #ekoparty2025

📅 Jueves, 23 Oct, 15:30 AST

22.10.2025 13:49 👍 0 🔁 0 💬 0 📌 0
Preview
GitHub Security Lab Securing open source software, together.

👋 Hola Argentina! We’re thrilled to be at #EkoParty this week!

If you’re around, swing by the GitHub booth — grab some stickers, play our security games, and chat with our experts about all things open source & security.

See you there 👉 gh.io/eko

22.10.2025 13:32 👍 2 🔁 0 💬 0 📌 0
Video thumbnail

The internet was on fire. 🔥
One small library affecting billions of systems.
Log4Shell was the biggest security vulnerability of all time.

Now, Log4J maintainer, Christian Grobmeier tells us what it felt like inside the flames 👉 github.blog/open-source/...

20.10.2025 18:37 👍 114 🔁 18 💬 5 📌 3
Flyer from the conference The Hack Summit announcing a presentation: 
Sylwia Budzynska, GitHub Security Researcher
From One Bug to Hundreds: Scaling Vulnerability Research with CodeQL

Flyer from the conference The Hack Summit announcing a presentation: Sylwia Budzynska, GitHub Security Researcher From One Bug to Hundreds: Scaling Vulnerability Research with CodeQL

Are you in Warsaw for The Hack Summit Warsaw? Join Sylwia Budzynska for an introductory talk about security research, static analysis, and CodeQL: "From One Bug to Hundreds: Scaling Vulnerability Research with CodeQL"

📆 October 14, 11:20 CEST
Track: Security in Software Development & DevSecOps

13.10.2025 16:27 👍 0 🔁 0 💬 0 📌 0
https://bounty.github.com

Here are our September bug bounty stats!
✅ 166 bounty reports submitted
👥 120 hackers participated in our program
💰 Awarded $113,008 in bounties
Found a vulnerability? Submit it here: t.co/HG2AqybW0p.

08.10.2025 17:24 👍 0 🔁 0 💬 0 📌 0
Preview
Protect Your Project Securing open source software, together.

⏱️ Maintainers, we know you don’t have time to research every security best practice. That’s why we’ve made it simple:

✅ 15 minutes
✅ No security expertise required
✅ Free for open source
✅ Quick wins with long-term impact

Protect your project now at gh.io/protect-your-project

30.09.2025 15:14 👍 11 🔁 2 💬 0 📌 0
Preview
Our plan for a more secure npm supply chain GitHub is strengthening npm's security with stricter authentication, granular tokens, and enhanced trusted publishing.

Recent account takeovers and attacks on package registries are a wake-up call: it's time to raise the bar on authentication and secure publishing practices. Find out what npm is doing—and what steps you can take—to help secure the open source supply chain: github.blog/security/sup...

23.09.2025 16:11 👍 3 🔁 3 💬 1 📌 0
https://bounty.github.com

Here are our August bug bounty stats!
✅ 173 bounty reports submitted
👥 131 hackers participated in our program
💰 Awarded $28,667 in bounties
Found a vulnerability? Submit it here: t.co/HG2AqybW0p.

12.09.2025 21:18 👍 1 🔁 0 💬 0 📌 0
Introducing cargo safe-publish About ways to publish unexpected code to crates.io

Georg Semmler, the maintainer of github.com/diesel-rs/di... and one of the recent participants in the GitHub Secure Open Source Fund, has written a tool called cargo-safe-publish that helps protect against supply chain attacks in the Rust Cargo ecosystem. Read more: blog.weiznich.de/blog/cargo-s...

02.09.2025 18:37 👍 2 🔁 1 💬 0 📌 0
Preview
Safeguarding VS Code against prompt injections See how to reduce the risks of an indirect prompt injection, such as the exposure of confidential files or the execution of code without the user's consent.

What if attackers could hijack your coding agent through a simple GitHub issue?

Prompt injections are a real and growing threat for VS Code Copilot Agent.

Learn how these attacks work and how you can defend your environment.

Read the full research: github.blog/security/vul...

25.08.2025 17:53 👍 5 🔁 2 💬 0 📌 0
LinkedIn Login, Sign in | LinkedIn Login to LinkedIn to keep in touch with people you know, share ideas, and build your career.

Join GitHub Open Source Friday - Aug 22, 10am PT - for a special episode featuring Bartosz Gałek and @jkcso.bsky.social, contributors to the Secure Code Game. Discover how Season 3 is empowering developers and students to build safer LLM-based applications.
www.linkedin.com/events/73635...

21.08.2025 21:53 👍 1 🔁 0 💬 0 📌 0
Preview
Securing the supply chain at scale: Starting with 71 important open source projects Learn how the GitHub Secure Open Source Fund helped 71 open source projects significantly improve their security posture.

🚀 GitHub is on a mission to supercharge open-source security! We've partnered with 71 key open-source projects, giving them tools, funding, and playbooks to boost security. 🔐
Want your project to be part of this effort? Now’s the time to get involved! 💪
🔗 Find out more: github.blog/open-source/...

11.08.2025 17:27 👍 3 🔁 1 💬 0 📌 1