
Bob Callaway
@rdcallaw
OSS Supply Chain Security @google. @projectsigstore @theopenssf Technical Advisory Council - Ex-Red Hat, NetApp, IBM. PhD ECE NCSU.
ID: 144962898
17-05-2010 19:40:36
499 Tweet
680 Followers
129 Following








ToB's Artur Cygan found code execution and DoS bugs after just a few hours of fuzzing ZBar, an open-source library for reading barcodes. tl;dr basic fuzz testing can reveal serious bugs - even in widely used software. blog.trailofbits.com/2024/10/31/fuzā¦

New blog post about OSS-Fuzz AI-powered fuzzing is live! We talk about what went into making LLMs work well enough for this use case to find 26 new vulnerabilities (including a CVE in OpenSSL), as well as what else we have planned to make this better. security.googleblog.com/2024/11/leveliā¦

On the heels of Googleās āBig Sleepā AI discovery of a real-world vulnerability, our OSS-Fuzz team identified and reported 26 vulnerabilities to open-source project maintainers by using AI-generated and enhanced fuzz targets. Read more here: security.googleblog.com/2024/11/leveliā¦









