writeups.xyz writeups.xyz / Teddy Katz (@Not_aardvark)

Title Vulnerabilities Programs Authors
Stealing a few more GitHub Actions secrets
Stealing arbitrary GitHub Actions secrets
Messing with GitHub's fork collaboration for fun and profit
Exploiting padding oracles with fixed IVs
How I accidentally took down GitHub Actions
Bypassing GitHub's OAuth flow