GitHub Security Lab

@securitylab.github.com

Securing open source software, together

Hey bounty hunters! GitHub updates its bug bounty program to improve how the company partners with the security research community. This update is designed to reduce ambiguity, prioritize the areas of highest risk, and improve the speed and quality of security outcomes. github.blog/security/nex...

Next chapter: Restructuring GitHub's bug bounty program

GitHub is making some significant changes to its bug bounty program, shifting its focus to give researchers a better experience.

github.blog

Are you in Krakow for EuroPython? Join Sylwia Budzynska for “Introduction to security research. Find a CVE with CodeQL” to learn how to look for vulnerabilities in code and query for them with CodeQL. 📆 Tuesday, 14th July ⏰ 13:45 📌 Kraków, Poland ep2026.europython.eu/session/intr...

Introduction to security research. Find a CVE with CodeQL.

Learn how to find security vulnerabilities at Introduction to security research. Find a CVE with CodeQL tutorial

ep2026.europython.eu

6 GitHub security settings every maintainer should enable this week. These won't make your project unhackable. Nothing will. What they do is close the easy doors... the ones attackers try first. Free, fast, and worth the few minutes it takes. 🔗 github.blog/security/6-s...

6 security settings every GitHub maintainer should enable this week

These six free settings will not make your project unhackable. Nothing will. What they will do is close the easy doors.

github.blog

Attending BSides Vilnius? Don't miss 📌 @yarlob.bsky.social 's session "LLM-assisted vulnerability hunting: hype vs. reality" to hear about the practical experience of using LLM for finding vulnerabilities in OSS such as Signal or 7-Zip! 📅 June 4, 16:45 EEST 📍 Vilnius, Lithuania 👉 bsidesvilnius.lt

BSides Vilnius 2026 — Security Theater | Cybersecurity Conference in Lithuania

BSides Vilnius 2026 — community-driven cybersecurity conference in Lithuania. Workshops, talks, and CTF on 3–4 June at Kablys. Join the infosec community.

bsidesvilnius.lt

On 25th April at 10AM, join @blazingwind.bsky.social for the workshop "Introduction to security research. Find a CVE with CodeQL" at the Linux Session organized by Akademickie Stowarzyszenie Informatyczne in Wroclaw, Poland! Check out more information on the conference's website: linuksowa.pl

20. Sesja Linuksowa | Wrocław, Polska

Sesja Linuksowa to największa w Polsce konferencja poświęcona Wolnemu Oprogramowaniu oraz najnowszym trendom w systemach z rodziny GNU/Linux.

linuksowa.pl

Building with AI? 🤖 Then you won’t want to miss tomorrow’s @devoxx.fr workshop with @xcorail.bsky.social and @jkcso.bsky.social — all about how to build robust AI-powered applications. Shall we play a Game? LLM Security in Practice m.devoxx.com/events/devox... 📍 Paris 142 🗓️ April 22, 10.30am CET

Devoxx Mobile Companion

Your ultimate companion for Devoxx conferences worldwide. Browse talks, speakers, schedules, and manage your personalized conference experience.

m.devoxx.com

AI agents that execute commands, browse the web, and coordinate with other agents are everywhere. But how do you know they're safe? We let you find out by hacking one yourself. Free, hands-on, and you can get started in under 2 minutes! Learn more in our latest blog. github.blog/security/hac...

Hack the AI agent: Build agentic AI security skills with the GitHub Secure Code Game

Learn to find and exploit real-world agentic AI vulnerabilities through five progressive challenges in this free, open source game that over 10,000 developers have already used to sharpen their securi...

github.blog

Reviewed advisories hit a four-year low, malware advisories surged, and CNA publishing grew—here’s what changed and what it means for your triage and response. Read Jonathan Evans's A year of open source vulnerability trends: CVEs, advisories, and malware github.blog/security/sup...

A year of open source vulnerability trends: CVEs, advisories, and malware

Reviewed advisories hit a four-year low, malware advisories surged, and CNA publishing grew—here’s what changed.

github.blog

Sign in with ANY password: How we used AI to break into a popular chat application, and other high-impact vulnerabilities. Read "How to scan for vulnerabilities with GitHub Security Lab’s open source AI-powered framework" github.blog/security/how...

How to scan for vulnerabilities with GitHub Security Lab’s open source AI-powered framework

GitHub Security Lab Taskflow Agent is very effective at finding Auth Bypasses, IDORs, Token Leaks, and other high-impact vulnerabilities.

github.blog

Excited to share our open source agentic framework for security research, a collaborative framework that lets the community share AI "taskflows”! Read @kevinbackhouse.bsky.social 's blog post for details and a demo. Join us in strengthening open-source security! github.blog/security/com...

Community-powered security with AI: an open source framework for security research

Announcing GitHub Security Lab Taskflow Agent, an open source and collaborative framework for security research with AI.

github.blog

GitHub Security Lab discovered a critical vulnerability in WooCommerce. We’d like to thank WooCommerce/Automattic for their incredibly quick response and fix of the vulnerability. If you are using WooCommerce, please update. For more info see: developer.woocommerce.com/2025/12/22/s...

Store API Vulnerability Patched in WooCommerce 8.1+ - What You Need To Know

A critical vulnerability in WooCommerce 8.1+ has been patched. We strongly recommend updating immediately.

developer.woocommerce.com