Make a deal with GitHub Security Lab
🔒 Paid proposals held safely in escrow — released only when the work's approved.
Known for
9 views
Proof of Concept for GHSL-2026-140 (CVE-2026-48095) in 7-Zip <= 26.00. A crafted archive shrinks a 256 MB buffer into 1 byte, overwrites a function pointer with file content, and redirects execution. Full weaponization needs an ASLR bypass. Fixed in 26.01. Read more at https://securitylab.github.com/advisories/GHSL-2026-140_7-Zip/
3 views
Your mother tongue is the new programing language for creating exploits.
For maintainer month, we took inspiration from #OpenClaw and built ProdBot! An intentionally vulnerable agent wired up with MCPs, skills, agentic workflows, and multi-agent capabilities. You will learn from it, while having fun!
Play now at: gh.io/secure-code-game
Learn more: https://github.blog/security/hack-the-ai-agent-bui
2 views
What happens when you hand an AI agent its own tools, memory, and a path to production?
Season 4 of the Secure Code Game is live, and this time the target is agentic AI security.
Meet ProdBot. An AI agent built to be broken. It runs on MCP servers, skills, and multi-agent workflows, and every layer is a door someone could walk through. Your job is to find the cracks before an attacker does.
Play n
📊 Post engagement
🔥 Top post: Proof of Concept for GHSL-2026-140 (CVE-2026-48095) in 7-Zip <= · 9 likes + reposts
📊 Activity & format
Recent posts
View on Mastodon ↗
▶
🔥 Top post
Proof of Concept for GHSL-2026-140 (CVE-2026-48095) in 7-Zip <= 26.00. A crafted archive shrinks a 256 MB buffer into 1 byte, overwrites a function pointer with file content, and redirects execution. Full weaponization needs an ASLR bypass. Fixed in 26.01. Read more at https://s…
▶
What happens when you hand an AI agent its own tools, memory, and a path to production?
Season 4 of the Secure Code Game is live, and this time the target is agentic AI security.
Meet ProdBot. An AI agent built to be broken. It runs on MCP…
Attending BSides Vilnius? Don't miss 📌 @yarlob 's session "LLM-assisted vulnerability hunting: hype vs. reality" to hear about the practical experience of using LLM for finding vulnerabilities in OSS such as Signal or 7-Zip!
📅 June 4, 16:4…
Who's at DevTalks? Join @jkcso and discover practical ways to use AI for security through 12 GitHub Copilot demos from secure coding, to informed supply chain decisions, and secure SDLC.
📅 June 4, 14:00 EEST
📍 Bucharest, Romania
👉 https:/…
Attending AI DevCon? Join Joseph Katsioloudes and discover practical ways to use AI for security through 12 GitHub Copilot demos from secure coding, to informed supply chain decisions, and secure SDLC.
📅 June 1, 10:00 AM BST
📍 London, UK &…
▶
Your mother tongue is the new programing language for creating exploits.
For maintainer month, we took inspiration from #OpenClaw and built ProdBot! An intentionally vulnerable agent wired up with MCPs, skills, agentic workflows, and multi…
On 25th April at 10AM, join @blazingwindsec
for the workshop "Introduction to security research. Find a CVE with CodeQL" at the Linux Session organized by Akademickie Stowarzyszenie Informatyczne in Wroclaw, Poland!
More information on t…
Building with AI? 🤖
Then you won’t want to miss tomorrow’s @devoxxfr workshop with @xcorail and @jkcso — all about how to build robust AI-powered applications.
Shall we play a Game? LLM Security in Practice
https://m.devoxx.com/events/devo…
Catch Shelby Cunningham on stage at CVE/FIRST VulnCon 2026 in Scottsdale, Arizona.
Her panel, “Supply Chains and Malware Campaigns: Is CVE the Right Way to Name the Game?”, examines whether CVE is the right tool for tracking open-source su…
🐘 Community & instance
💡 Facts
🕵️ Fake follower check
Estimated- Est. 92% real, active audience · Low fake-follower risk.
- Engagement (~0.7% of followers engage each post) is around typical for Mastodon.
- Verified account.
- Established account (3+ years old).
Heuristic estimate from engagement, follower ratios, account age & growth — a screening signal, not a guarantee.
About
📸 Gallery
🔀 Audience overlap
EstimatedEstimated shared audience with similar creators — useful for avoiding overlap (or doubling down) when planning a campaign.
More like this
Find more →✉ Message GitHub Security Lab
Reaching out to influencers is a Pro feature. Upgrade to message any influencer directly — perfect for brands and agencies booking sponsorships.
- ✓ Message any influencer from their listing
- ✓ The influencer gets notified by email
- ✓ Manage every conversation in one inbox
Already Pro? Log in.
🎤 Event / appearance with GitHub Security Lab
Booking an event / appearance is a Pro feature. Upgrade to book GitHub Security Lab for an in-person or virtual appearance — payment held safely in escrow until the event is done.
- ✓ Book them for events, livestreams, panels & more
- ✓ GitHub Security Lab gets notified by email
- ✓ Fee held in escrow, released after the appearance
Already Pro? Log in.
You're out of free requests this month
Free accounts get 5 per month. Go Pro for unlimited sponsor pitches, collab requests & sponsorship deals — plus featured placement, the Verified badge, free withdrawals and more.
Upgrade to Pro — $9.95/mo →Your free limit resets on the 1st of next month.