πš‘πšπŸΎ

@hg8.sh

Security Researcher & Privacy Activist. DM are welcome for any questions. -- Website: https://hg8.sh Post history on Twitter: @_hg8_

"Weaponizing Dependabot: Pwn Request at its finest" TL;DR: Through "Confused Deputy" attacks Dependabot (and other GitHub bots), can be tricked into merging malicious code. It can escalate to full command injection via crafted branch names. boostsecurity.io/blog/weaponi... #infosec

Weaponizing Dependabot: Pwn Request at its finest

Learn how Dependabot can be co-opted to exploit some sensitive workflows, through the Confused Deputy Problem and branch name injections.

boostsecurity.io

Three Trail of Bits engineers audited core Go cryptography for a month and found only one low-sev security issue... in unsupported Go+BoringCrypto! 🍾 Years of efforts on testing, limiting complexity, safe APIs, and readability have paid off! ✨ Yes I am taking a victory lap. No I am not sorry. πŸ†

Go Cryptography Security Audit

Go's cryptography libraries underwent an audit by Trail of Bits. Read more about the scope and results.

go.dev