Hey developer friends, anyone want to test drive a new security feature for GitHub next week?
Happy to reimburse you for your time!
Darakian
@Hooray_Darakian
Joined March 2021
Darakian’s Tweets
📣 I am extremely proud to share that this is publicly available now! the goal of this initiative at the is to help researchers while they're disclosing vuls to open source projects and provide guidance and support 💜
Quote Tweet
Coordination is Key! New Guide for Security Researchers to Coordinate Vulnerability Disclosures with #OSS Projects provides valuable best practices on how Finders can best engage & work with the open source community on discovered vulnerabilities hubs.la/Q01mnyBg0 #OSSummit
6
9
The following number is prime:
77777777777777777777777797777777777777777777777777
13
92
510
Show this thread
In this post "Corrupting memory without memory corruption" is showing how a powerful kernel bug, CVE-2022-20186, can be used to root a Pixel 6 from a malicious app
1
47
120
Jaroslav Lobačevski, Senior Security Researcher , is speaking next week!
Register now to see his talk 'Securing GitHub Actions 101'
⛵ Waikīkī Marriott Resort
🏝️ O'ahu, Hawai'i
☀️ June 27-30th
🌟
🌟
🎟️ locomocosec.com
4
5
Curious phish attempt. Text from `U-S-P-S` about a package not being deliverable with some `t.co` link. Private browser it and I see a good recreation of the usps site and asked to pay three dollars. The curious part is that I had sent a package and it was late
NIST PQC Selection ETA: End of March.
1
30
43
Show this thread
This is the first in a series of ships to make GitHub's advisory database easier for the community to contribute to. All the data at github.com/advisories is creative commons licensed, and over the next few months it's going to increasingly feel like an open source project
Quote Tweet
Exciting new feature for GitHub security advisories, but the real treasure was learning to spell "unreviewed" along the way.
github.blog/changelog/2021
1
5
10
Show this thread
Learn how to fuzz Adobe Reader and finding bugs in closed-source applications in exercise 8 of Fuzzing 101 : github.co/fuzzing101
112
343
this morning we detected multiple versions of the “coa” package published with malicious code due to a compromised account of a maintainer. we quickly removed the compromised versions and have published an advisory: github.com/advisories/GHS. npm itself was not compromised. [1/3]
7
165
155
Show this thread
GitHub has revoked weakly-generated SSH keys added to accounts due to a vulnerability in a library used by GitKraken and other third-party clients and integrators. Read more here github.blog/2021-10-11-git.
1
40
63
The GitHub Advisory Database now includes curated rust advisories!
Rust joins Composer, Go, Maven, npm, NuGet, pip, and RubyGems as our latest supported ecosystem.
4
30
99
New set of OWASP top 10 for 2021
owasp.org/Top10/
Surprisingly the root cause for Benny Jacob's CVE-2021-26084 reported on by and is CVE-2020-17530, which I reported in 2020. For help with impact, root cause, and variant analysis for your org, see the advisory at securitylab.github.com/advisories/GHS 1/n
2
26
112
Show this thread
As a follow-up to our March 8, 2021 announcement about logging out all GitHub users, we're sharing the details of how we found and fixed the rare race condition in our session handling.
6
83
194













