logo

GitHub Security Lab

ID: 9fc9a491-4d37-5eae-8ade-879f147f388f

STIX ID: identity--9fc9a491-4d37-5eae-8ade-879f147f388f

Feed Type: rss

Earliest post: 2025-03-24

Latest post: 2026-04-14

Security research, vulnerability findings, secure coding guidance, and tooling updates from the GitHub Security Lab team — focused on improving open-source safety and advancing community-driven security practices.

01/01/2020
06/04/2026
Title Date Published Describes IncidentAuthorVisible
Securing the open source supply chain across GitHub2026-04-01TrueZachary SteindlerTrue
A year of open source vulnerability trends: CVEs, advisories, and malware2026-03-26TrueJonathan EvansTrue
How to scan for vulnerabilities with GitHub Security Lab’s open source AI-powered framework2026-03-06TrueMan Yue MoTrue
Bugs that survive the heat of continuous fuzzing2025-12-29TrueAntonio MoralesTrue
Strengthening supply chain security: Preparing for the next malware campaign2025-12-23TrueMadison OliverTrue
Our plan for a more secure npm supply chain2025-09-23TrueXavier René-CorailTrue
Safeguarding VS Code against prompt injections2025-08-25TrueMichael StepankinTrue
Modeling CORS frameworks with CodeQL to find security vulnerabilities2025-07-10TrueKevin StubbingsTrue
CVE-2025-53367: An exploitable out-of-bounds write in DjVuLibre2025-07-03TrueKevin BackhouseTrue
DNS rebinding attacks explained: The lookup is coming from inside the house!2025-06-03TrueJaroslav LobacevskiTrue
Bypassing MTE with CVE-2025-00722025-05-23TrueMan Yue MoTrue
Localhost dangers: CORS and DNS rebinding2025-04-03TrueKevin StubbingsTrue

1–12 of 12