# fuzzing

Published articles for fuzzing.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Sound Open Firmware 2.15 Released With AMD ACP 7.x Support, Intel UAOL

DevFeed: [Sound Open Firmware 2.15 Released With AMD ACP 7.x Support, Intel UAOL](<https://devfeed.tech/articles/sound-open-firmware-2-15-released-with-amd-acp-7-x-support-intel-uaol-26768.md>)

Original publisher: [Read original article](<https://www.phoronix.com/news/Sound-Open-Firmware-2.15>)

Author: Michael Larabel

Published: 2026-09-15T13:04:40Z

Content type: release

Language: en

Sources: [Phoronix](<https://devfeed.tech/sources/phoronix.md>)

Topics: [Embedded Software Dev](<https://devfeed.tech/topics/embedded-software-dev.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [intel](<https://devfeed.tech/topics/intel.md>), [Security](<https://devfeed.tech/topics/security.md>), [qemu](<https://devfeed.tech/topics/qemu.md>), [Xtensa](<https://devfeed.tech/topics/xtensa.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [POSIX](<https://devfeed.tech/topics/posix.md>), [Testing](<https://devfeed.tech/topics/testing.md>)

Tags: [desktop-linux](<https://devfeed.tech/tags/desktop-linux.md>), [driver](<https://devfeed.tech/tags/driver.md>), [dsp](<https://devfeed.tech/tags/dsp.md>), [firmware](<https://devfeed.tech/tags/firmware.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [intel](<https://devfeed.tech/tags/intel.md>), [linux-benchmarking](<https://devfeed.tech/tags/linux-benchmarking.md>), [linux-hardware-benchmarks](<https://devfeed.tech/tags/linux-hardware-benchmarks.md>), [linux-hardware-reviews](<https://devfeed.tech/tags/linux-hardware-reviews.md>), [linux-how-to](<https://devfeed.tech/tags/linux-how-to.md>), [linux-performance](<https://devfeed.tech/tags/linux-performance.md>), [linux-server-benchmarks](<https://devfeed.tech/tags/linux-server-benchmarks.md>), [open](<https://devfeed.tech/tags/open.md>), [open-source-graphics](<https://devfeed.tech/tags/open-source-graphics.md>), [phoronix](<https://devfeed.tech/tags/phoronix.md>), [phoronix-test-suite](<https://devfeed.tech/tags/phoronix-test-suite.md>), [posix](<https://devfeed.tech/tags/posix.md>), [processor](<https://devfeed.tech/tags/processor.md>), [qemu](<https://devfeed.tech/tags/qemu.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [ubuntu-benchmarks](<https://devfeed.tech/tags/ubuntu-benchmarks.md>), [ubuntu-hardware](<https://devfeed.tech/tags/ubuntu-hardware.md>), [usb](<https://devfeed.tech/tags/usb.md>), [xtensa](<https://devfeed.tech/tags/xtensa.md>)

### AI overview

Sound Open Firmware 2.15 adds user-space, memory-protected module execution, AMD ACP 7.x and NXP i.MX8MP support, Intel UAOL USB audio offload, testing targets, security hardening, and new audio processing modules.

### Source excerpt

Sound Open Firmware as the open-source, vendor-independent audio DSP firmware stack and driver framework is out today with a new feature update...

## Join Us at the Zephyr Project Meetup in Amsterdam

DevFeed: [Join Us at the Zephyr Project Meetup in Amsterdam](<https://devfeed.tech/articles/join-us-at-the-zephyr-project-meetup-in-amsterdam-8798.md>)

Original publisher: [Read original article](<https://blog.jetbrains.com/clion/2026/09/join-us-at-the-zephyr-project-meetup-in-amsterdam/>)

Author: Maria Goldade

Published: 2026-09-10T10:37:58Z

Content type: article

Language: en

Sources: [The JetBrains Blog](<https://devfeed.tech/sources/the-jetbrains-blog.md>)

Topics: [Embedded Software Dev](<https://devfeed.tech/topics/embedded-software-dev.md>), [Operating system](<https://devfeed.tech/topics/operating-system.md>), [developer tooling](<https://devfeed.tech/topics/developer-tooling.md>), [migration](<https://devfeed.tech/topics/migration.md>)

Tags: [community](<https://devfeed.tech/tags/community.md>), [embedded](<https://devfeed.tech/tags/embedded.md>), [events](<https://devfeed.tech/tags/events.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [migration](<https://devfeed.tech/tags/migration.md>), [news](<https://devfeed.tech/tags/news.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

An invitation to a Zephyr Project meetup in Amsterdam, featuring talks on embedded development, tooling, firmware fuzzing, AI-assisted setup, and migration to Zephyr.

### Source excerpt

Register for the Meetup On September 15, the Zephyr community is coming together for an in-person meetup at the JetBrains office in Amsterdam. The Zephyr Project is an open-source collaboration project hosted by the Linux Foundation. Its community brings together developers, users, silicon vendors, device manufacturers, and software companies to build a small, scalable real-time [...]

## What to expect at the Zephyr Project Meetup (September 15, 2026) - Amsterdam, Netherlands

DevFeed: [What to expect at the Zephyr Project Meetup (September 15, 2026) - Amsterdam, Netherlands](<https://devfeed.tech/articles/what-to-expect-at-the-zephyr-project-meetup-september-15-2026-amsterdam-netherlands-13982.md>)

Original publisher: [Read original article](<https://www.zephyrproject.org/what-to-expect-at-the-zephyr-project-meetup-september-15-2026-amsterdam-netherlands/>)

Author: Susan Remmert

Published: 2026-09-09T05:00:04Z

Content type: article

Language: en

Sources: [Zephyr Project](<https://devfeed.tech/sources/zephyr-project.md>)

Topics: [Zephyr RTOS](<https://devfeed.tech/topics/zephyr-rtos.md>), [Embedded Systems](<https://devfeed.tech/topics/embedded-systems.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [simulator](<https://devfeed.tech/topics/simulator.md>), [developer tooling](<https://devfeed.tech/topics/developer-tooling.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [blog](<https://devfeed.tech/tags/blog.md>), [bugs](<https://devfeed.tech/tags/bugs.md>), [community](<https://devfeed.tech/tags/community.md>), [contributors](<https://devfeed.tech/tags/contributors.md>), [embedded](<https://devfeed.tech/tags/embedded.md>), [embedded-systems](<https://devfeed.tech/tags/embedded-systems.md>), [event](<https://devfeed.tech/tags/event.md>), [events](<https://devfeed.tech/tags/events.md>), [firmware](<https://devfeed.tech/tags/firmware.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [harness](<https://devfeed.tech/tags/harness.md>), [meetup](<https://devfeed.tech/tags/meetup.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [simulator](<https://devfeed.tech/tags/simulator.md>), [talk](<https://devfeed.tech/tags/talk.md>), [technologies](<https://devfeed.tech/tags/technologies.md>), [tooling](<https://devfeed.tech/tags/tooling.md>), [tools](<https://devfeed.tech/tags/tools.md>), [zephyr](<https://devfeed.tech/tags/zephyr.md>)

### AI overview

The Zephyr Project Meetup in Amsterdam on September 15, 2026, will bring together embedded developers, contributors, students, and engineers to exchange practical knowledge about Zephyr RTOS. The agenda includes talks on JetBrains' work with Zephyr, fuzzing Zephyr applications with AFL and Renode, and making hardware development easier with Schematik.

### Source excerpt

What are developers in the Netherlands building with Zephyr? On September 15, the embedded community will meet in Amsterdam to exchange practical knowledge, discuss current work, and learn more about the Zephyr RTOS. The event is open to experienced contributors, first-time users, students, engineers, and anyone curious about open source embedded development.

## What to expect at the Zephyr Project Meetup (September 15, 2026) - Amsterdam, Netherlands

DevFeed: [What to expect at the Zephyr Project Meetup (September 15, 2026) - Amsterdam, Netherlands](<https://devfeed.tech/articles/what-to-expect-at-the-zephyr-project-meetup-september-15-2026-amsterdam-netherlands-38677.md>)

Original publisher: [Read original article](<https://zephyrproject.org/what-to-expect-at-the-zephyr-project-meetup-september-15-2026-amsterdam-netherlands/>)

Author: Susan Remmert

Published: 2026-09-09T05:00:04Z

Content type: news

Language: en

Sources: [Zephyr Project](<https://devfeed.tech/sources/zephyr-project-2.md>)

Topics: [Zephyr RTOS](<https://devfeed.tech/topics/zephyr-rtos.md>), [Embedded Systems](<https://devfeed.tech/topics/embedded-systems.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [blog](<https://devfeed.tech/tags/blog.md>), [c](<https://devfeed.tech/tags/c.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [crashes](<https://devfeed.tech/tags/crashes.md>), [developer-tooling](<https://devfeed.tech/tags/developer-tooling.md>), [embedded](<https://devfeed.tech/tags/embedded.md>), [embedded-systems](<https://devfeed.tech/tags/embedded-systems.md>), [event](<https://devfeed.tech/tags/event.md>), [events](<https://devfeed.tech/tags/events.md>), [firmware](<https://devfeed.tech/tags/firmware.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [harness](<https://devfeed.tech/tags/harness.md>), [jetbrains](<https://devfeed.tech/tags/jetbrains.md>), [meetup](<https://devfeed.tech/tags/meetup.md>), [memory-corruption](<https://devfeed.tech/tags/memory-corruption.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [simulator](<https://devfeed.tech/tags/simulator.md>), [zephyr](<https://devfeed.tech/tags/zephyr.md>)

### AI overview

The Zephyr Project Meetup in Amsterdam on September 15, 2026, will bring together embedded developers, contributors, students, and engineers to share practical knowledge about Zephyr RTOS. The agenda includes talks on JetBrains' work with Zephyr, fuzzing Zephyr with AFL and Renode, and making hardware development easier with Schematik.

### Source excerpt

What are developers in the Netherlands building with Zephyr? On September 15, the embedded community will meet in Amsterdam to exchange practical knowledge, discuss current work, and learn more about the Zephyr RTOS. The event is open to experienced contributors, first-time users, students, engineers, and anyone curious about open source embedded development.

## Stronger with every update: How we're making Chrome and the web safer in the AI Era

DevFeed: [Stronger with every update: How we're making Chrome and the web safer in the AI Era](<https://devfeed.tech/articles/stronger-with-every-update-how-we-re-making-chrome-and-the-web-safer-in-the-ai-era-7623.md>)

Original publisher: [Read original article](<https://blog.google/security/chrome-stronger-with-every-update/>)

Author: Chrome Security Team

Published: 2026-07-30T17:00:00Z

Content type: article

Language: en

Sources: [Security](<https://devfeed.tech/sources/security.md>)

Topics: [Chrome](<https://devfeed.tech/topics/chrome.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Agent Harness](<https://devfeed.tech/topics/agent-harness.md>), [V8](<https://devfeed.tech/topics/v8.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [interoperability](<https://devfeed.tech/topics/interoperability.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-models](<https://devfeed.tech/tags/ai-models.md>), [bug](<https://devfeed.tech/tags/bug.md>), [bugs](<https://devfeed.tech/tags/bugs.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [chrome-security](<https://devfeed.tech/tags/chrome-security.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [interoperability](<https://devfeed.tech/tags/interoperability.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [none](<https://devfeed.tech/tags/none.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article describes how Chrome's security teams use large language models, fuzzing, specialized research tools, and AI vulnerability-discovery agents to find and remediate security bugs more quickly. It highlights Big Sleep, an agent harness using Gemini, model interoperability, and a Chrome knowledge base built from CVEs and Git history.

### Source excerpt

Video of Chrome logo turning into a shield

## From Finding to Fixing: Reducing maintainer burden with automated patches

DevFeed: [From Finding to Fixing: Reducing maintainer burden with automated patches](<https://devfeed.tech/articles/from-finding-to-fixing-reducing-maintainer-burden-with-automated-patches-7624.md>)

Original publisher: [Read original article](<https://blog.google/security/from-finding-to-fixing-reducing-maintainer-burden-with-automated-patches/>)

Author: Dustin Ingram

Published: 2026-07-29T16:00:00Z

Content type: article

Language: en

Sources: [Security](<https://devfeed.tech/sources/security.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI Bots](<https://devfeed.tech/topics/ai-bots.md>)

Tags: [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [none](<https://devfeed.tech/tags/none.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [validation](<https://devfeed.tech/tags/validation.md>)

### AI overview

The article describes an OSS-Fuzz pipeline that sends validated vulnerability findings to CodeMender, which analyzes root causes and produces tested patches to reduce the fixing burden on open-source maintainers.

### Source excerpt

Since its launch in 2016, OSS-Fuzz has contributed significantly to making open-source secure by finding and reporting tens of thousands of bugs. But finding more vulner...

## GPT-5.5-Cyber built a zlib fuzzing lab in a day

DevFeed: [GPT-5.5-Cyber built a zlib fuzzing lab in a day](<https://devfeed.tech/articles/gpt-5-5-cyber-built-a-zlib-fuzzing-lab-in-a-day-7656.md>)

Original publisher: [Read original article](<https://blog.trailofbits.com/2026/07/02/field-reports-from-patch-the-planet/>)

Author: "Benjamin Samuels"

Published: 2026-07-02T11:00:00Z

Content type: article

Language: en

Sources: [The Trail of Bits Blog](<https://devfeed.tech/sources/the-trail-of-bits-blog.md>), [The Trail of Bits Blog](<https://devfeed.tech/sources/the-trail-of-bits-blog-2.md>)

Topics: [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI Chat](<https://devfeed.tech/topics/ai-chat.md>)

Tags: [bugs](<https://devfeed.tech/tags/bugs.md>), [codex](<https://devfeed.tech/tags/codex.md>), [compression](<https://devfeed.tech/tags/compression.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [gpt](<https://devfeed.tech/tags/gpt.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openai](<https://devfeed.tech/tags/openai.md>), [patch-the-planet](<https://devfeed.tech/tags/patch-the-planet.md>), [security](<https://devfeed.tech/tags/security.md>), [tooling](<https://devfeed.tech/tags/tooling.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Trail of Bits reports that GPT-5.5-Cyber built a fuzzing campaign for zlib in a day, using sanitizer and variant builds, harnesses, and seeds. The effort is part of Patch the Planet, which aims to find and patch security bugs in open-source projects with maintainers.

### Source excerpt

We're running Patch the Planet, an ongoing collaboration with OpenAI that pairs Trail of Bits engineers directly with more than 30 open-source projects. Its goal is to front-run a serious problem facing open-source maintainers: highly capable models like GPT-5.5-Cyber will soon create a firehose of bug reports, and OSS maintainers are already spread thin. Our plan is to point OpenAI's latest models at real codebases, find the security bugs first, work with maintainers to patch them, and find ways to decrease the burden on maintainers in the long run. We'll publish field reports like this one as the initiative progresses; follow along via the Patch the Planet tag. The expertise barrier that kept bespoke fuzzing campaigns out of reach for most attackers is gone. We watched GPT-5.5-Cyber build in a single day what would have taken weeks for a skilled security researcher: harnesses across a dozen entrypoints, sanitizer and variant builds, seeds, and multiple findings currently undergoing coordinated disclosure. This particular instance focused on zlib, a widely used data format and lossless data compression software library. We pointed GPT-5.5-Cyber at the library and drove it through Codex with the /goal command, asking it to find a specific class of bugs that are critically dangerous in compression libraries. We'll publish the full harness and findings for inspection once the vulnerabilities are patched and a new release is cut. The lab GPT-5.5-Cyber built in a day We didn't tell the model how to find these bugs. The obvious first move is to read the source code, but zlib has been reviewed so thoroughly that there's little left to find that way. GPT-5.5-Cyber worked that out for itself, judged static review to be a poor use of tokens, and decided the higher value path was to build fuzz tooling to dynamically test the code. Earlier models given the same goal tend to read the code and flag whatever looks suspicious, ultimately leading to mediocre outcomes. We believe th

## Introducing Patch the Planet

DevFeed: [Introducing Patch the Planet](<https://devfeed.tech/articles/introducing-patch-the-planet-7654.md>)

Original publisher: [Read original article](<https://blog.trailofbits.com/2026/06/22/introducing-patch-the-planet/>)

Author: "Trail of Bits"

Published: 2026-06-22T16:50:00Z

Content type: article

Language: en

Sources: [The Trail of Bits Blog](<https://devfeed.tech/sources/the-trail-of-bits-blog.md>), [The Trail of Bits Blog](<https://devfeed.tech/sources/the-trail-of-bits-blog-2.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [pull-requests](<https://devfeed.tech/topics/pull-requests.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [networking](<https://devfeed.tech/topics/networking.md>), [cURL](<https://devfeed.tech/topics/curl.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>)

Tags: [announcements](<https://devfeed.tech/tags/announcements.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [go](<https://devfeed.tech/tags/go.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [networking](<https://devfeed.tech/tags/networking.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openai](<https://devfeed.tech/tags/openai.md>), [patch-the-planet](<https://devfeed.tech/tags/patch-the-planet.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Patch the Planet pairs Trail of Bits engineers and open-source maintainers with frontier models to discover, triage, and fix security issues. Its first week produced hundreds of bugs, 64 pull requests, and 51 issues across 19 projects, with work also adding tests, fuzzing harnesses, CI security scanning, supply-chain tooling, correctness fixes, and features.

### Source excerpt

What happens when you clear dozens of Trail of Bits engineers' schedules, pair them with every open-source maintainer they can contact, and unleash the latest frontier models like GPT-5.5-Cyber on critical open-source targets? Thanks to our partnership with OpenAI and its Daybreak initiative, we can report that the impact is hundreds of discovered bugs, 64 pull requests, and 51 issues filed across 19 projects (with many more still undergoing coordinated disclosure). That was just the first week of Patch the Planet. Frontier models like GPT-5.5-Cyber are producing a firehose of security findings, and already-stretched maintainers must sift through all of it to separate real vulnerabilities from plausible-sounding false positives. Patch the Planet is different: with our experts orchestrating and triaging findings, we handle the work of fixing and hardening the code alongside the people who maintain it. The first week of Patch the Planet covered 19 projects across cryptography, networking, language infrastructure, and software supply chain. Among these 19 projects were cURL, NATS, pyca, Sigstore, aiohttp, the Go project, freenginx, Python and python.org, urllib3, PyPI, SimpleX, Valkey, and RustCrypto. Over 30 projects have joined the initiative so far, and we're rapidly expanding it to include more; if you maintain an open-source project, apply to join! Live look at the Trail of Bits engineering teams Anyone can file an issue, flex, and walk away. We showed up with the patches: 37 are already merged, and many more are in flight. These merges go beyond just fixing bugs: we're adding new tests and fuzzing harnesses, CI security scanning, supply-chain tooling, correctness fixes, and features maintainers had been meaning to get to. The goal of Patch the Planet is to leave essential open-source projects measurably better off. We brought patches, not just bug reports We're reporting public findings on GitHub, including 64 total pull requests. We also filed 51 issues, 19 of w

## Choosing Values for Robust Tests

DevFeed: [Choosing Values for Robust Tests](<https://devfeed.tech/articles/choosing-values-for-robust-tests-23871.md>)

Original publisher: [Read original article](<http://testing.googleblog.com/2026/06/choosing-values-for-robust-tests.html>)

Author: Google Testing Bloggers (noreply@blogger.com)

Published: 2026-06-04T12:47:00Z

Content type: tutorial

Language: en

Sources: [Google Testing Blog](<https://devfeed.tech/sources/google-testing-blog.md>)

Topics: [Testing](<https://devfeed.tech/topics/testing.md>), [test](<https://devfeed.tech/topics/test.md>), [Code](<https://devfeed.tech/topics/code.md>), [implementation](<https://devfeed.tech/topics/implementation.md>), [bug](<https://devfeed.tech/topics/bug.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [bug](<https://devfeed.tech/tags/bug.md>), [code](<https://devfeed.tech/tags/code.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [implementation](<https://devfeed.tech/tags/implementation.md>), [radion-khait](<https://devfeed.tech/tags/radion-khait.md>), [test](<https://devfeed.tech/tags/test.md>), [testing](<https://devfeed.tech/tags/testing.md>), [tests](<https://devfeed.tech/tags/tests.md>), [tott](<https://devfeed.tech/tags/tott.md>), [unit-test](<https://devfeed.tech/tags/unit-test.md>)

### AI overview

The article explains how default-valued test inputs can let broken implementations pass unnoticed. It recommends non-default values, varied scenarios, boundary and special-case inputs, fuzzing, and distinct values for each parameter to improve test coverage and confidence.

### Source excerpt

This article was adapted from a Google Tech on the Toilet (TotT) episode. You can download a printer-friendly version of this TotT episode and post it in your office. By Radion Khait A test passes. Great! But does it really mean your code is working as expected? Not necessarily.Sometimes the values you choose in your tests can create a false sense of security, especially when dealing with default values. Consider this snippet of a simple map class and its corresponding unit test: Implementation Test void MyMap::insert(int key, int value) { // Oops! The map entry is default-initialized, // the second parameter is not used. internal_map_[key]; } TEST(MyMapTest, Insert) { MyMap my_map; my_map.insert(1, 0); // This passes! EXPECT_EQ(my_map.get(1), 0); } The test passes, but the insert method is broken! It never actually stores the value. The test only passes because the default value for an integer in the map (0) happens to match the value used in the test. When choosing test values, consider the following: Test with non-default values. Explicitly test with values different from the type's default (e.g., non-zero numbers, non-empty strings, enum values other than the one at index 0). This provides greater confidence that your code is actually using the provided input. TEST(MyMapTest, Insert) { MyMap my_map; my_map.insert(1, 5); // This test would fail and reveal the bug in // the implementation above: "Expected 5, got 0". EXPECT_EQ(my_map.get(1), 5); } Test multiple inputs that cover different scenarios, where it is reasonable to do so. Consider empty/missing/null values, numerical boundaries, and special cases that trigger complex logic. Try to cover all distinct code/logic paths. Consider using fuzzing to more thoroughly cover the input domain. Use different values for each input. This guarantees the code under test doesn't accidentally reuse a single input or switch their order. Parameterized testing can also help test a large variety of inputs with minimal code dupl

## gosentry brings LibAFL-grade fuzzing to Go's native interface

DevFeed: [gosentry brings LibAFL-grade fuzzing to Go's native interface](<https://devfeed.tech/articles/gosentry-brings-libafl-grade-fuzzing-to-go-s-native-interface-7650.md>)

Original publisher: [Read original article](<https://blog.trailofbits.com/2026/05/12/go-fuzzing-was-missing-half-the-toolkit.-we-forked-the-toolchain-to-fix-it./>)

Author: "Kevin Valerio"

Published: 2026-05-12T11:00:00Z

Content type: article

Language: en

Sources: [The Trail of Bits Blog](<https://devfeed.tech/sources/the-trail-of-bits-blog.md>), [The Trail of Bits Blog](<https://devfeed.tech/sources/the-trail-of-bits-blog-2.md>)

Topics: [Go Language](<https://devfeed.tech/topics/go-language.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>)

Tags: [bug](<https://devfeed.tech/tags/bug.md>), [c](<https://devfeed.tech/tags/c.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [cache](<https://devfeed.tech/tags/cache.md>), [cli](<https://devfeed.tech/tags/cli.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [go](<https://devfeed.tech/tags/go.md>), [research-practice](<https://devfeed.tech/tags/research-practice.md>), [rust](<https://devfeed.tech/tags/rust.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [tool-release](<https://devfeed.tech/tags/tool-release.md>), [toolchain](<https://devfeed.tech/tags/toolchain.md>), [tooling](<https://devfeed.tech/tags/tooling.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

Gosentry is a fuzzing-oriented fork of the Go toolchain that retains Go's native fuzzing interface while using LibAFL by default. It adds native struct fuzzing, Nautilus grammar-based fuzzing, additional bug detection, and campaign coverage reporting without requiring existing Go fuzz harnesses to be rewritten.

### Source excerpt

Go's native fuzzing is useful, but it stands far behind state-of-the-art tooling that the Rust, C, and C++ ecosystems offer with LibAFL and AFL++. Path constraints are hard to solve. Structured inputs usually need handmade parsing. It doesn't even detect several common bug classes, such as integer overflows, goroutine leaks, data races, and execution timeouts. So to make it better, we built gosentry, a fuzzing-oriented fork of the Go toolchain that keeps the standard testing.F workflow while using a stronger fuzzing stack underneath to tackle those issues. With gosentry, go test -fuzz uses LibAFL by default. It can fuzz structs natively, run grammar-based fuzzing with Nautilus, detect bug classes that it couldn't detect before, and create a fuzzing campaign coverage report in one command. If you already have Go fuzz harnesses, you don't need to rewrite them. Point them at gosentry's binary and you get all of the above through the same go test -fuzz interface, with a few new flags: ./bin/go test -fuzz=FuzzHarness --focus-on-new-code=false --catch-races=true --catch-leaks=true Figure 1: Basic gosentry usage gosentry keeps the harness API and changes the engine and the surrounding tooling -- you just tweak the CLI. You can also generate coverage reports from an existing campaign with --generate-coverage. Run it from the same package with the same -fuzz target, and no corpus path is needed; gosentry stores the campaign state under Go's fuzz cache index by package and fuzz target, so restarting the campaign resumes from the existing corpus. Why we built gosentry We started this project after we released go-panikint to improve Go fuzzing's integer overflow detection. We realized that integer overflow detection wasn't enough. Go's fuzzing ecosystem was still missing techniques that Rust, C, and C++ researchers already use every day. We often faced these gaps in our own security work using Go's vanilla fuzzer: Program comparisons (path constraints) were impossible to solve:

## New Logic for Programmers (and the future of this newsletter)

DevFeed: [New Logic for Programmers (and the future of this newsletter)](<https://devfeed.tech/articles/new-logic-for-programmers-and-the-future-of-this-newsletter-25497.md>)

Original publisher: [Read original article](<https://buttondown.com/hillelwayne/archive/new-logic-for-programmers-and-the-future-of-this/>)

Author: Hillel Wayne

Published: 2026-05-06T17:03:46Z

Content type: opinion

Language: en

Sources: [Newsletter feed for Hillel Wayne's Newsletter](<https://devfeed.tech/sources/newsletter-feed-for-hillel-wayne-s-newsletter.md>)

Topics: [Formal methods](<https://devfeed.tech/topics/formal-methods.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Programming](<https://devfeed.tech/topics/programming.md>)

Tags: [developer](<https://devfeed.tech/tags/developer.md>), [formal-methods](<https://devfeed.tech/tags/formal-methods.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [newsletter](<https://devfeed.tech/tags/newsletter.md>), [release](<https://devfeed.tech/tags/release.md>), [testing](<https://devfeed.tech/tags/testing.md>), [updates](<https://devfeed.tech/tags/updates.md>)

### AI overview

The author announces version 0.14 of Logic for Programmers, reports progress toward a 1.0 print edition, and shares plans to join Antithesis as a developer educator. The newsletter may shift toward software history and related topics, with its future publishing frequency uncertain.

### Source excerpt

So first the immediate news: I just released version 0.14 of Logic for Programmers! This release is pretty similar to 0.13. There are a few rewrites but the vast majority of the changes are layout, copyediting, and technical editing. Full notes here. In related news, I've started doing test prints of the book: There's not a whole lot left to be done. I've gotta fix up some diagrams, do more formatting and proofreading, incorporate some fixes raised by readers, and make a website and back cover. After that, the book should be ready for 1.0. I'm aiming to have print copies purchasable by the end of June! Now the big news: starting August, I'll be a full-time employee of Antithesis, a generative testing platform. Officially my role is "developer educator", and I'll be tasked with making "property-based testing, fuzzing, fault injection, Hegel, Bombadil, and the Antithesis platform understandable to everyday engineers". So the same kind of work I do now, except with far more support and a matching 401(k). I already have three pages of topic ideas you have no idea how excited I am about this So how is this going to affect the newsletter? First, I want to make clear that this is not going to become an Antithesis newsletter. My Antithesis-related work is going to be on their official platforms. I do think one of the best ways to make a topic "understandable" is to write foundational material that's useful to all engineers, whether they're invested in the topic or not. I might share links to things I make along those lines, but they'll be just that, links. At the same time, the content of this newsletter will change a little. Property testing and fuzzing aren't the same as formal methods, but a lot of the foundations overlap, especially in how we think about properties and correctness. I don't know for sure yet, but I suspect that I'll start biasing this newsletter away from Antithesis related topics. So there will probably be less theoretic things like what does undecidabl

## Extending Ruzzy with LibAFL

DevFeed: [Extending Ruzzy with LibAFL](<https://devfeed.tech/articles/extending-ruzzy-with-libafl-7648.md>)

Original publisher: [Read original article](<https://blog.trailofbits.com/2026/04/29/extending-ruzzy-with-libafl/>)

Author: "Matt Schwager"

Published: 2026-04-29T11:00:00Z

Content type: article

Language: en

Sources: [The Trail of Bits Blog](<https://devfeed.tech/sources/the-trail-of-bits-blog.md>), [The Trail of Bits Blog](<https://devfeed.tech/sources/the-trail-of-bits-blog-2.md>)

Topics: [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Ruby](<https://devfeed.tech/topics/ruby.md>), [Rust](<https://devfeed.tech/topics/rust.md>), [LLVM](<https://devfeed.tech/topics/llvm.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [complex-systems](<https://devfeed.tech/tags/complex-systems.md>), [developers](<https://devfeed.tech/tags/developers.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [linux](<https://devfeed.tech/tags/linux.md>), [llvm](<https://devfeed.tech/tags/llvm.md>), [ruby](<https://devfeed.tech/tags/ruby.md>), [rust](<https://devfeed.tech/tags/rust.md>), [tool-release](<https://devfeed.tech/tags/tool-release.md>), [tools](<https://devfeed.tech/tags/tools.md>)

### AI overview

The article describes adding LibAFL support to Ruzzy, a coverage-guided fuzzer for pure Ruby code and Ruby C extensions. It covers building LibAFL as a standalone library, integrating it through a Dockerfile, and investigating ELF and linker issues encountered during the integration.

### Source excerpt

LibAFL is all the rage in the fuzzing community these days, especially with LLVM's libFuzzer being placed in maintenance mode. Written in Rust, LibAFL claims improved performance, modularity, state-of-the-art fuzzing techniques, and libFuzzer compatibility. For these reasons, I set out to add LibAFL support to Ruzzy, our coverage-guided fuzzer for pure Ruby code and Ruby C extensions. This gives Ruby developers and security researchers access to a more advanced and actively maintained fuzzing engine without changing how they write their fuzzing harnesses. Ruzzy was originally built on top of LLVM's libFuzzer, so using LibAFL's compatibility layer should be easy enough. However, digging around in the internals of complex systems is never quite as simple as it seems. In this post, I will investigate some of the deep plumbing inside these fuzzing engines, take a detour into executable and linkable format (ELF) files, and ultimately add LibAFL support to Ruzzy. Building with libafl_libfuzzer Ruzzy currently supports Linux, so I use a Dockerfile for development and for production fuzzing campaigns. To that end, using a similar Dockerfile for LibAFL support is the simplest integration point. LibAFL provides excellent documentation and build scripts to use it as a standalone library. We need to build LibAFL as a standalone library because Ruzzy uses libFuzzer as a library. Following along with the standalone libafl_libfuzzer documentation, and with the build.sh script in hand, we can build libFuzzer.a. This is the archive that will ultimately be linked into Ruzzy's C extension and used to fuzz our target. Here are the relevant lines from our new Dockerfile: # Install Rust nightly via rustup RUN wget -qO- https://sh.rustup.rs | sh -s -- \ -y \ --default-toolchain nightly \ --component llvm-tools ENV PATH="/root/.cargo/bin:${PATH}" # Clone LibAFL RUN git clone --depth 1 https://github.com/AFLplusplus/LibAFL /libafl # Build libFuzzer.a from LibAFL's libfuzzer runtime WORKDIR

## Wasmtime's April 9, 2026 Security Advisories

DevFeed: [Wasmtime's April 9, 2026 Security Advisories](<https://devfeed.tech/articles/wasmtime-s-april-9-2026-security-advisories-15143.md>)

Original publisher: [Read original article](<https://bytecodealliance.org/articles/wasmtime-security-advisories>)

Author: The Wasmtime Project Maintainers

Published: 2026-04-09T00:00:00Z

Content type: news

Language: en

Sources: [Bytecode Alliance](<https://devfeed.tech/sources/bytecode-alliance.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [releases](<https://devfeed.tech/topics/releases.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Rust](<https://devfeed.tech/topics/rust.md>), [WebAssembly](<https://devfeed.tech/topics/web-assembly.md>), [Machine Learning, Security Attacks](<https://devfeed.tech/topics/machine-learning-security-attacks.md>), [Mozilla](<https://devfeed.tech/topics/mozilla.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [audit](<https://devfeed.tech/tags/audit.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [llm](<https://devfeed.tech/tags/llm.md>), [mozilla](<https://devfeed.tech/tags/mozilla.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [release](<https://devfeed.tech/tags/release.md>), [releases](<https://devfeed.tech/tags/releases.md>), [rust](<https://devfeed.tech/tags/rust.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [webassembly](<https://devfeed.tech/tags/webassembly.md>)

### AI overview

The Wasmtime team released versions 43.0.1, 42.0.2, 36.0.7, and 24.0.7 with fixes for 12 security advisories, including two rated Critical. The team says 11 advisories were found using new LLM-based tools and recommends that users upgrade.

### Source excerpt

A new world for security-critical projects

## Introduction to Fuzzing ESP-IDF components

DevFeed: [Introduction to Fuzzing ESP-IDF components](<https://devfeed.tech/articles/introduction-to-fuzzing-esp-idf-components-13743.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/2026/01/fuzzing/>)

Author: John Lee

Published: 2026-01-07T00:00:00Z

Content type: tutorial

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [ESP-IDF](<https://devfeed.tech/topics/esp-idf.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [c/c++](<https://devfeed.tech/topics/c-c-plus-plus.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [c-c-plus-plus](<https://devfeed.tech/tags/c-c-plus-plus.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [component](<https://devfeed.tech/tags/component.md>), [embedded](<https://devfeed.tech/tags/embedded.md>), [esp-idf](<https://devfeed.tech/tags/esp-idf.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This article introduces fuzzing for ESP-IDF components and embedded libraries. It explains how to fuzz host-compiled code with sanitizers, compares black-box, grey-box, and white-box approaches, and outlines workflows using a basic mutator, AFL++, and protocol-focused harnesses.

### Source excerpt

This article introduces fuzzing -- a technique for finding vulnerabilities -- and demonstrates practical workflows and lessons learned for ESP-IDF components and embedded libraries in general.

## exploits.club Weekly Newsletter 90 - Fuzzing Rust Subsystems, Pwn2Own Near Misses, Linux 1-Days, And More

DevFeed: [exploits.club Weekly Newsletter 90 - Fuzzing Rust Subsystems, Pwn2Own Near Misses, Linux 1-Days, And More](<https://devfeed.tech/articles/exploits-club-weekly-newsletter-90-fuzzing-rust-subsystems-pwn2own-near-misses-linux-1-days-and-more-32647.md>)

Original publisher: [Read original article](<https://blog.exploits.club/exploits-club-weekly-newsletter-90-fuzzing-rust-subsystems-pwn2own-near-misses-linux-1-days-and-more/>)

Author: exploits.club

Published: 2025-10-23T17:00:02Z

Content type: news

Language: en

Sources: [exploits.club](<https://devfeed.tech/sources/exploits-club.md>)

Topics: [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Rust](<https://devfeed.tech/topics/rust.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Security](<https://devfeed.tech/topics/security.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [network security](<https://devfeed.tech/topics/network-security.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [Parsing](<https://devfeed.tech/topics/parsing.md>)

Tags: [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux](<https://devfeed.tech/tags/linux.md>), [network-security](<https://devfeed.tech/tags/network-security.md>), [parsing](<https://devfeed.tech/tags/parsing.md>), [rce](<https://devfeed.tech/tags/rce.md>), [rust](<https://devfeed.tech/tags/rust.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This weekly newsletter rounds up security research and developer-related resources, including fuzzing of Rust code in the Windows kernel, a WatchGuard Fireware OS vulnerability analysis, and a near-miss Pwn2Own printer exploit write-up.

### Source excerpt

Good thing that absolutely no drama whatsoever took place for US vuln research firms this week...annnnnyways 👇 In Case You Missed It... OffensiveCon CFP - Closes March 1st, 2026 so let the procrastination begin! RE//Verse CFP - These need to be in by November 14th, so a bit less procrastinating.

## Trace similarity systems on top of ClickHouse to analyze crash stack traces from our CI

DevFeed: [Trace similarity systems on top of ClickHouse to analyze crash stack traces from our CI](<https://devfeed.tech/articles/trace-similarity-systems-on-top-of-clickhouse-to-analyze-crash-stack-traces-from-our-ci-5607.md>)

Original publisher: [Read original article](<https://clickhouse.com/blog/trace-similarity-stack-traces>)

Author: Misha Shiryaev

Published: 2025-09-24T12:46:35Z

Content type: article

Language: en

Sources: [ClickHouse Blog](<https://devfeed.tech/sources/clickhouse-blog.md>)

Topics: [clickhouse](<https://devfeed.tech/topics/clickhouse.md>), [ci](<https://devfeed.tech/topics/ci.md>), [Traces](<https://devfeed.tech/topics/traces.md>), [issue tracker](<https://devfeed.tech/topics/issue-tracker.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [FIRST](<https://devfeed.tech/topics/first.md>)

Tags: [ci](<https://devfeed.tech/tags/ci.md>), [clickhouse](<https://devfeed.tech/tags/clickhouse.md>), [crash-reporting](<https://devfeed.tech/tags/crash-reporting.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [github](<https://devfeed.tech/tags/github.md>), [issue-tracker](<https://devfeed.tech/tags/issue-tracker.md>), [logs](<https://devfeed.tech/tags/logs.md>), [trace](<https://devfeed.tech/tags/trace.md>)

### AI overview

This article explains how to build a trace similarity system on top of ClickHouse to analyze crash stack traces from CI. It describes collecting crash reports, extracting stack frames, grouping similar traces, and creating or updating GitHub issues so teams can distinguish new bugs from known ones.

### Source excerpt

Learn how our engineering team cut through noisy CI crash reports with a trace similarity system built on ClickHouse.

## WebSocket Turbo Intruder: Unearthing the WebSocket Goldmine

DevFeed: [WebSocket Turbo Intruder: Unearthing the WebSocket Goldmine](<https://devfeed.tech/articles/websocket-turbo-intruder-unearthing-the-websocket-goldmine-7720.md>)

Original publisher: [Read original article](<https://portswigger.net/research/websocket-turbo-intruder-unearthing-the-websocket-goldmine>)

Author: Zakhar Fedotkin

Published: 2025-09-17T12:40:06Z

Content type: tutorial

Language: en

Sources: [PortSwigger Research](<https://devfeed.tech/sources/portswigger-research.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [extension](<https://devfeed.tech/tags/extension.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [json](<https://devfeed.tech/tags/json.md>), [python](<https://devfeed.tech/tags/python.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article introduces WebSocket Turbo Intruder, a Burp Suite extension for high-volume fuzzing of WebSocket messages with custom Python code. It explains WebSocket-testing challenges, installation, built-in tools, and a basic message-testing example.

### Source excerpt

Many testers and tools give up the moment a protocol upgrade to WebSocket occurs, or only perform shallow analysis. This is a huge blind spot, leaving many bugs like Broken Access Controls, Race condi

## exploits.club Weekly Newsletter 85 -Fuzzing KSMBD, Kernel-Hack-Drill, Vibe-Crashing, And More

DevFeed: [exploits.club Weekly Newsletter 85 -Fuzzing KSMBD, Kernel-Hack-Drill, Vibe-Crashing, And More](<https://devfeed.tech/articles/exploits-club-weekly-newsletter-85-fuzzing-ksmbd-kernel-hack-drill-vibe-crashing-and-more-32642.md>)

Original publisher: [Read original article](<https://blog.exploits.club/exploits-club-weekly-newsletter-85-fuzzing-ksmbd-kernel-hack-drill-vibe-crashing-and-more/>)

Author: exploits.club

Published: 2025-09-04T15:00:32Z

Content type: article

Language: en

Sources: [exploits.club](<https://devfeed.tech/sources/exploits-club.md>)

Topics: [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Linux Kernel](<https://devfeed.tech/topics/linux-kernel.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Security](<https://devfeed.tech/topics/security.md>), [race-condition](<https://devfeed.tech/topics/race-condition.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Ubuntu](<https://devfeed.tech/topics/ubuntu.md>)

Tags: [exploits](<https://devfeed.tech/tags/exploits.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux-kernel](<https://devfeed.tech/tags/linux-kernel.md>), [race-condition](<https://devfeed.tech/tags/race-condition.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The 85th exploits.club weekly newsletter highlights work on fuzzing improvements and vulnerability discovery in ksmbd, including 23 reported bugs. It also covers Kernel-Hack-Drill research on exploiting CVE-2024-50264, a Linux kernel socket race condition resulting in use-after-free, and related exploitation constraints.

### Source excerpt

New idea - let AI submit a different, buzzwordy talks to every CFP. What could go wrong? Annnnnnnnyways 👇 In Case You Missed It... 0-day Hunting Strategy with Eugene "Spaceraccoon" Lim - Following the release of his recent No Starch Press book, @spaceraccoonsec will be on tomorrow'

## exploits.club Weekly Newsletter 80 - ITW Windows Bugs, Deterministic iOS Exploits, Pwn2Own Firefox Vulns, and More

DevFeed: [exploits.club Weekly Newsletter 80 - ITW Windows Bugs, Deterministic iOS Exploits, Pwn2Own Firefox Vulns, and More](<https://devfeed.tech/articles/exploits-club-weekly-newsletter-80-itw-windows-bugs-deterministic-ios-exploits-pwn2own-firefox-vulns-and-more-32637.md>)

Original publisher: [Read original article](<https://blog.exploits.club/exploits-club-weekly-newsletter-80-itw-windows-bugs-deterministic-ios-exploits-pwn2own-firefox-vulns-and-more/>)

Author: exploits.club

Published: 2025-07-24T15:21:15Z

Content type: news

Language: en

Sources: [exploits.club](<https://devfeed.tech/sources/exploits-club.md>)

Topics: [iOS](<https://devfeed.tech/topics/ios.md>), [Firefox](<https://devfeed.tech/topics/firefox.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [bug](<https://devfeed.tech/topics/bug.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [IO](<https://devfeed.tech/topics/io.md>), [Mozilla](<https://devfeed.tech/topics/mozilla.md>)

Tags: [bugs](<https://devfeed.tech/tags/bugs.md>), [cve](<https://devfeed.tech/tags/cve.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [firefox](<https://devfeed.tech/tags/firefox.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [ios](<https://devfeed.tech/tags/ios.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [love](<https://devfeed.tech/tags/love.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

This issue of exploits.club Weekly Newsletter reviews recent security research and resources, including white-box fuzzing with AFL++, deterministic iOS kernel exploits extended to additional chipsets, an analysis of the Windows vulnerability CVE-2025-29824 and its use in the wild, and a Mozilla Firefox vulnerability discussed in connection with Pwn2Own.

### Source excerpt

The Cameraman at that Coldplay concert pic.twitter.com/MHtqBxbwC6 -- Hater Report (@HaterReport_) July 18, 2025 Annnnnnnyways 👇 80 NEWSLETTERS 🎉 In Case You Missed It... Fuzzing 1001: Introductory white-box fuzzing with AFL++ - new course from OST2! Pwnie Nominees for 2025 - Released this week. Check them out!! Resources

## Xen Project 4.20: A Step Forward in Open Source Virtualization

DevFeed: [Xen Project 4.20: A Step Forward in Open Source Virtualization](<https://devfeed.tech/articles/xen-project-4-20-a-step-forward-in-open-source-virtualization-12838.md>)

Original publisher: [Read original article](<https://xenproject.org/blog/xen-project-4-20-oss-virtualization/>)

Author: Cody Zuschlag

Published: 2025-03-11T13:30:38Z

Content type: article

Language: en

Sources: [Blog - Xen Project](<https://devfeed.tech/sources/blog-xen-project.md>)

Topics: [virtualization](<https://devfeed.tech/topics/virtualization.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Optimization](<https://devfeed.tech/topics/optimization.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [amd](<https://devfeed.tech/tags/amd.md>), [announcements](<https://devfeed.tech/tags/announcements.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [intel](<https://devfeed.tech/tags/intel.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [optimization](<https://devfeed.tech/tags/optimization.md>), [performance](<https://devfeed.tech/tags/performance.md>), [release](<https://devfeed.tech/tags/release.md>), [releases](<https://devfeed.tech/tags/releases.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [virtualization](<https://devfeed.tech/tags/virtualization.md>), [xen-4-20](<https://devfeed.tech/tags/xen-4-20.md>)

### AI overview

The article discusses the Xen Project's Xen 4.20 release as an open-source virtualization update. It highlights security improvements, including expanded MISRA C compliance, fuzzing, and UBSAN enabled by default, along with performance optimizations for page-table management, cache utilization, device passthrough, Intel CPUs, and AMD Zen 5. The release is presented as targeting cloud, enterprise, and embedded-system workloads.

### Source excerpt

Xen 4.20 is here! 🚀 This release boosts security, performance, and architecture support, shaping the future of open-source virtualization.

## ClickHouse at FOSDEM 2025: talks, tech, and a community dinner

DevFeed: [ClickHouse at FOSDEM 2025: talks, tech, and a community dinner](<https://devfeed.tech/articles/clickhouse-at-fosdem-2025-talks-tech-and-a-community-dinner-5071.md>)

Original publisher: [Read original article](<https://clickhouse.com/blog/clickhouse-at-fosdem-2025>)

Author: Tyler Hannan

Published: 2025-02-25T15:08:26Z

Content type: article

Language: en

Sources: [ClickHouse Blog](<https://devfeed.tech/sources/clickhouse-blog.md>)

Topics: [clickhouse](<https://devfeed.tech/topics/clickhouse.md>), [JSON](<https://devfeed.tech/topics/json.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [clickhouse](<https://devfeed.tech/tags/clickhouse.md>), [community](<https://devfeed.tech/tags/community.md>), [databases](<https://devfeed.tech/tags/databases.md>), [deep-dive](<https://devfeed.tech/tags/deep-dive.md>), [developers](<https://devfeed.tech/tags/developers.md>), [fosdem](<https://devfeed.tech/tags/fosdem.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [json](<https://devfeed.tech/tags/json.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [tech](<https://devfeed.tech/tags/tech.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

A recap of ClickHouse's presence at FOSDEM 2025, covering a talk on its new powerful JSON data type and another on the challenges of fuzzing databases. The JSON presentation discusses column-oriented storage, dynamically changing structures, and fast querying of individual JSON paths.

### Source excerpt

This year, ClickHouse made a strong showing at FOSDEM 2025, with several team members traveling to Belgium and multiple talks covering everything from powerful new JSON data types to the challenges of fuzzing databases.

## BuzzHouse: Bridging the database fuzzing gap for testing ClickHouse

DevFeed: [BuzzHouse: Bridging the database fuzzing gap for testing ClickHouse](<https://devfeed.tech/articles/buzzhouse-bridging-the-database-fuzzing-gap-for-testing-clickhouse-5019.md>)

Original publisher: [Read original article](<https://clickhouse.com/blog/buzzhouse-bridging-the-database-fuzzing-gap-for-testing-clickhouse>)

Author: Pedro Ferreira

Published: 2025-01-21T00:00:00Z

Content type: article

Language: en

Sources: [ClickHouse Blog](<https://devfeed.tech/sources/clickhouse-blog.md>)

Topics: [Developer Tools](<https://devfeed.tech/topics/developer-tools.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [bugs](<https://devfeed.tech/tags/bugs.md>), [clickhouse](<https://devfeed.tech/tags/clickhouse.md>), [database](<https://devfeed.tech/tags/database.md>), [databases](<https://devfeed.tech/tags/databases.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [software-testing](<https://devfeed.tech/tags/software-testing.md>), [sql](<https://devfeed.tech/tags/sql.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

The article introduces BuzzHouse, a ClickHouse fuzzer designed to generate complex, correct SQL queries and close gaps in database testing. It explains fuzz testing, why database fuzzing is difficult, and how fuzzing can uncover bugs, crashes, and vulnerabilities.

### Source excerpt

Discover how Pedro, our QA expert, built BuzzHouse--a fuzzer that's closed critical gaps and found over 100 issues in ClickHouse.

## Concealing payloads in URL credentials

DevFeed: [Concealing payloads in URL credentials](<https://devfeed.tech/articles/concealing-payloads-in-url-credentials-7671.md>)

Original publisher: [Read original article](<https://portswigger.net/research/concealing-payloads-in-url-credentials>)

Author: Gareth Heyes

Published: 2024-10-23T12:59:05Z

Content type: article

Language: en

Sources: [PortSwigger Research](<https://devfeed.tech/sources/portswigger-research.md>)

Topics: [payload](<https://devfeed.tech/topics/payload.md>), [browsers](<https://devfeed.tech/topics/browsers.md>), [Chrome](<https://devfeed.tech/topics/chrome.md>), [Firefox](<https://devfeed.tech/topics/firefox.md>), [Document Object Model (DOM)](<https://devfeed.tech/topics/dom.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Redirection](<https://devfeed.tech/topics/redirection.md>)

Tags: [browsers](<https://devfeed.tech/tags/browsers.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [firefox](<https://devfeed.tech/tags/firefox.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [payload](<https://devfeed.tech/tags/payload.md>), [redirection](<https://devfeed.tech/tags/redirection.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains how payloads can be concealed in the credentials portion of URLs while remaining hidden from the address bars of Chrome and Firefox. It examines differences between document.URL and location, Firefox's handling of single quotes, and applications to DOM XSS, anchor credentials, redirection, and DOM clobbering. Safari discards URL credentials, so the described examples work only in Chrome and Firefox.

### Source excerpt

Last year Johan Carlsson discovered you could conceal payloads inside the credentials part of the URL . This was fascinating to me especially because the payload is not actually visible in the URL in

## FuzzSlice: Separating real CVEs from fakes through fuzzing

DevFeed: [FuzzSlice: Separating real CVEs from fakes through fuzzing](<https://devfeed.tech/articles/fuzzslice-separating-real-cves-from-fakes-through-fuzzing-13055.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/fuzzslice-separating-real-cves-from-fakes-through-fuzzing>)

Published: 2024-09-19T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [Security](<https://devfeed.tech/topics/security.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>)

Tags: [cves](<https://devfeed.tech/tags/cves.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

Chainguard Labs presents FuzzSlice, a fuzzing technique for determining whether CVEs are exploitable within an application context. In an evaluation of 18 OpenSSL CVEs, it classified 12 as exploitable and six as unreachable or false positives.

### Source excerpt

Chainguard Labs explores FuzzSlice, a novel fuzzing technique, to improve vulnerability remediation by distinguishing exploitable CVEs from false positives.

[Next page](<https://devfeed.tech/tags/fuzzing.md?cursor=WyIyMDI0LTA5LTE5VDAwOjAwOjAwKzAwOjAwIiwgImI4YTVhZGFiLTliNjAtNDhiZi04NDkyLTg3ZmM1MzM3Y2E0OCJd>)