<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-07-27T09:35:41Z</updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by GitHub Security Lab</title>
  <author>
    <name>GitHub Security Lab</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub1p3vejjq7hv2xzyaep8fslldw5murgn8lfahyegp5ev8t7d9few2qqur8jg.rss" />
  <link href="https://nostr.ae/npub1p3vejjq7hv2xzyaep8fslldw5murgn8lfahyegp5ev8t7d9few2qqur8jg" />
  <id>https://nostr.ae/npub1p3vejjq7hv2xzyaep8fslldw5murgn8lfahyegp5ev8t7d9few2qqur8jg</id>
  <icon>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/287/682/946/591/880/original/be5f23331ebe9143.png</icon>
  <logo>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/287/682/946/591/880/original/be5f23331ebe9143.png</logo>




  <entry>
    <id>https://nostr.ae/nevent1qqsyd7ag5cfps87ly03gyu0xlkwyuf8vwsh0u63wk5jv7rrega5gnyqzyqx9nx2gr6a3gcgnhyyaxrla46n0sdzvla8kun9qxn9sa0e5489egnz69lm</id>
    
      <title type="html">Proof of Concept for GHSL-2026-140 (CVE-2026-48095) in 7-Zip ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsyd7ag5cfps87ly03gyu0xlkwyuf8vwsh0u63wk5jv7rrega5gnyqzyqx9nx2gr6a3gcgnhyyaxrla46n0sdzvla8kun9qxn9sa0e5489egnz69lm" />
    <content type="html">
      Proof of Concept for GHSL-2026-140 (CVE-2026-48095) in 7-Zip &amp;lt;= 26.00. A crafted archive shrinks a 256 MB buffer into 1 byte, overwrites a function pointer with file content, and redirects execution. Full weaponization needs an ASLR bypass. Fixed in 26.01. Read more at &lt;a href=&#34;https://securitylab.github.com/advisories/GHSL-2026-140_7-Zip/&#34;&gt;https://securitylab.github.com/advisories/GHSL-2026-140_7-Zip/&lt;/a&gt;&lt;br/&gt;&lt;video controls width=&#34;100%&#34; class=&#34;max-h-[90vh] bg-neutral-300 dark:bg-zinc-700&#34;&gt;&lt;source src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/647/726/654/108/998/original/58f55c0a4db3bb17.mp4&#34;&gt;&lt;/video&gt;&lt;br/&gt;
    </content>
    <updated>2026-05-27T17:31:29Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqwpzaf0022pkwzhqterxw6qx6gjnhmp6mdtk2nxwa2nu2d0um9fczyqx9nx2gr6a3gcgnhyyaxrla46n0sdzvla8kun9qxn9sa0e5489egfeq0y4</id>
    
      <title type="html">Learn why some vulnerabilities resist to fuzzing and persist in ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqwpzaf0022pkwzhqterxw6qx6gjnhmp6mdtk2nxwa2nu2d0um9fczyqx9nx2gr6a3gcgnhyyaxrla46n0sdzvla8kun9qxn9sa0e5489egfeq0y4" />
    <content type="html">
      Learn why some vulnerabilities resist to fuzzing and persist in long-enrolled OSS-Fuzz projects, and how you can find them!&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.blog/security/vulnerability-research/bugs-that-survive-the-heat-of-continuous-fuzzing/&#34;&gt;https://github.blog/security/vulnerability-research/bugs-that-survive-the-heat-of-continuous-fuzzing/&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/807/671/946/648/986/original/e6b97148503fd187.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-12-30T08:58:30Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqst6pp6vna6694v987s5ff0ysndpmlnx2l03qpu4c9z0y48nnughtqzyqx9nx2gr6a3gcgnhyyaxrla46n0sdzvla8kun9qxn9sa0e5489egefgzsy</id>
    
      <title type="html">Here are our June bug bounty stats! ✅ 120 bounty reports ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqst6pp6vna6694v987s5ff0ysndpmlnx2l03qpu4c9z0y48nnughtqzyqx9nx2gr6a3gcgnhyyaxrla46n0sdzvla8kun9qxn9sa0e5489egefgzsy" />
    <content type="html">
      Here are our June bug bounty stats!&lt;br/&gt;✅ 120 bounty reports submitted&lt;br/&gt;👥 103 hackers participated in our program&lt;br/&gt;💰 Awarded $43,651 in bounties&lt;br/&gt;&lt;br/&gt;Found a vulnerability? Submit it here: &lt;a href=&#34;https://bounty.github.com&#34;&gt;https://bounty.github.com&lt;/a&gt;
    </content>
    <updated>2025-07-02T00:24:11Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsg7a60ushvhjhpllyjnq3ntmpj2j4f8ny7vsmh8pz6dr4ejreahqqzyqx9nx2gr6a3gcgnhyyaxrla46n0sdzvla8kun9qxn9sa0e5489eg283pll</id>
    
      <title type="html">Open source maintainers, did you receive your first vulnerability ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsg7a60ushvhjhpllyjnq3ntmpj2j4f8ny7vsmh8pz6dr4ejreahqqzyqx9nx2gr6a3gcgnhyyaxrla46n0sdzvla8kun9qxn9sa0e5489eg283pll" />
    <content type="html">
      Open source maintainers, did you receive your first vulnerability report? Don&amp;#39;t panic! Handling vulnerability reports doesn’t have to be stressful. Read on to find out how you can tackle security issues efficiently and confidently with the right tools and approach. &lt;a href=&#34;https://github.blog/security/vulnerability-research/a-maintainers-guide-to-vulnerability-disclosure-github-tools-to-make-it-simple/&#34;&gt;https://github.blog/security/vulnerability-research/a-maintainers-guide-to-vulnerability-disclosure-github-tools-to-make-it-simple/&lt;/a&gt;
    </content>
    <updated>2025-03-24T17:48:34Z</updated>
  </entry>

</feed>