Opens profile photo
Follow
Click to Follow GHSecurityLab
GitHub Security Lab
@GHSecurityLab
GitHub Security Lab’s mission is to inspire and enable the community to secure the open source software we all depend on.
securitylab.github.comJoined October 2019

GitHub Security Lab’s Tweets

It turns out that the first "all Google" phone includes a non-Google bug. Join on his journey through reporting the bug, and the exploit used to gain arbitrary kernel code execution and root on a Pixel 6 from an Android app.
42
Collaboration is the name of the game! Let's provide OWASP with feedback through this survey so that we can improve the user experience for all.
Quote Tweet
Help needed! Together with Netguru we're conducting a user experience study to understand how people use owasp.org today, what works and what doesn't and to be able to change it for the better. Survey takes 3 minutes! - netguru.typeform.com/to/fxi3Qlp8
13
The CTF will be jeopardy-style with challenges from all major categories such as crypto, pwn, reversing, web, misc and more exotic ones like #CodeQL as well. If you ever wanted to try CodeQL, this is your excuse for spending time on it :P Prizes: 1st: $500 2nd: $300 3rd: $200
Quote Tweet
We are proud to announce our first ever CTF! It starts on the next weekend already, so don't miss it 🍿 Date: Friday, 09 Dec. 2022, 18:00 UTC - Saturday, 10 Dec. 2022, 23:59 UTC More information at ctf.kitctf.me
Image
1
9
Show this thread
Thanks to and for helping us by reporting a serious security vulnerability. We take security very seriously and managed to patch the issue within one hour. You can find more details about the vulnerability in the quoted article.
Quote Tweet
GHSL-2022-069: Remote Code Execution (RCE) in CircuitVerse - CVE-2022-36038 securitylab.github.com/advisories/GHS
18
This Tuesday, we are at #OSMC in Nuremberg, Germany! Join us to learn more about Security as Code (SaC) and the latest initiatives we pursue to secure open source.
Quote Tweet
In his #OSMC talk @jkcso from @GHSecurityLab will review lessons learned from #DevOps to implement a thriving #DevSecOps culture. Check it out for more: osmc.de/talks/a-mainta
Image
1
8
With CodeQL for Ruby out of Beta, we are including it as part of the supported languages for our CodeQL Bug Bounty program. To celebrate, Ruby submissions will be awarded special bonuses. Learn more 🔗 securitylab.github.com/bounties/
Quote Tweet
GitHub Codespaces for all, GitHub Copilot for Business, improved code navigation on GitHub.com, and much, much more. 🚀 Check out all the exciting updates that we announced today at #GitHubUniverse: github.blog/2022-11-09-eve
10