Security Sign in as anyone: Bypassing SAML SSO authentication with parser differentials Critical authentication bypass vulnerabilities (CVE-2025-25291 + CVE-2025-25292) were discovered in ruby-saml up to version 1.17.0. In this blog post, we’ll shed light on how these vulnerabilities that rely on a parser differential were uncovered.
Security Full exposure: A practical approach to handling sensitive data leaks Treating exposures as full and complete can help you respond more effectively to focus on what truly matters: securing systems, protecting sensitive data, and maintaining the trust of stakeholders.
Engineering How GitHub uses CodeQL to secure GitHub How GitHub’s Product Security Engineering team manages our CodeQL implementation at scale and how you can, too.