# Fuzzing/Fuzz testing

Fuzzing, or fuzz testing, is an automated software testing technique that supplies invalid, unexpected, or random inputs to programs and monitors them for crashes, vulnerabilities, or other undesirable behavior.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Sound Open Firmware 2.15 Released With AMD ACP 7.x Support, Intel UAOL

DevFeed: [Sound Open Firmware 2.15 Released With AMD ACP 7.x Support, Intel UAOL](<https://devfeed.tech/articles/sound-open-firmware-2-15-released-with-amd-acp-7-x-support-intel-uaol-26768.md>)

Original publisher: [Read original article](<https://www.phoronix.com/news/Sound-Open-Firmware-2.15>)

Author: Michael Larabel

Published: 2026-09-15T13:04:40Z

Content type: release

Language: en

Sources: [Phoronix](<https://devfeed.tech/sources/phoronix.md>)

Topics: [Embedded Software Dev](<https://devfeed.tech/topics/embedded-software-dev.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [intel](<https://devfeed.tech/topics/intel.md>), [Security](<https://devfeed.tech/topics/security.md>), [qemu](<https://devfeed.tech/topics/qemu.md>), [Xtensa](<https://devfeed.tech/topics/xtensa.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [POSIX](<https://devfeed.tech/topics/posix.md>), [Testing](<https://devfeed.tech/topics/testing.md>)

Tags: [desktop-linux](<https://devfeed.tech/tags/desktop-linux.md>), [driver](<https://devfeed.tech/tags/driver.md>), [dsp](<https://devfeed.tech/tags/dsp.md>), [firmware](<https://devfeed.tech/tags/firmware.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [intel](<https://devfeed.tech/tags/intel.md>), [linux-benchmarking](<https://devfeed.tech/tags/linux-benchmarking.md>), [linux-hardware-benchmarks](<https://devfeed.tech/tags/linux-hardware-benchmarks.md>), [linux-hardware-reviews](<https://devfeed.tech/tags/linux-hardware-reviews.md>), [linux-how-to](<https://devfeed.tech/tags/linux-how-to.md>), [linux-performance](<https://devfeed.tech/tags/linux-performance.md>), [linux-server-benchmarks](<https://devfeed.tech/tags/linux-server-benchmarks.md>), [open](<https://devfeed.tech/tags/open.md>), [open-source-graphics](<https://devfeed.tech/tags/open-source-graphics.md>), [phoronix](<https://devfeed.tech/tags/phoronix.md>), [phoronix-test-suite](<https://devfeed.tech/tags/phoronix-test-suite.md>), [posix](<https://devfeed.tech/tags/posix.md>), [processor](<https://devfeed.tech/tags/processor.md>), [qemu](<https://devfeed.tech/tags/qemu.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [ubuntu-benchmarks](<https://devfeed.tech/tags/ubuntu-benchmarks.md>), [ubuntu-hardware](<https://devfeed.tech/tags/ubuntu-hardware.md>), [usb](<https://devfeed.tech/tags/usb.md>), [xtensa](<https://devfeed.tech/tags/xtensa.md>)

### AI overview

Sound Open Firmware 2.15 adds user-space, memory-protected module execution, AMD ACP 7.x and NXP i.MX8MP support, Intel UAOL USB audio offload, testing targets, security hardening, and new audio processing modules.

### Source excerpt

Sound Open Firmware as the open-source, vendor-independent audio DSP firmware stack and driver framework is out today with a new feature update...

## What to expect at the Zephyr Project Meetup (September 15, 2026) - Amsterdam, Netherlands

DevFeed: [What to expect at the Zephyr Project Meetup (September 15, 2026) - Amsterdam, Netherlands](<https://devfeed.tech/articles/what-to-expect-at-the-zephyr-project-meetup-september-15-2026-amsterdam-netherlands-13982.md>)

Original publisher: [Read original article](<https://www.zephyrproject.org/what-to-expect-at-the-zephyr-project-meetup-september-15-2026-amsterdam-netherlands/>)

Author: Susan Remmert

Published: 2026-09-09T05:00:04Z

Content type: article

Language: en

Sources: [Zephyr Project](<https://devfeed.tech/sources/zephyr-project.md>)

Topics: [Zephyr RTOS](<https://devfeed.tech/topics/zephyr-rtos.md>), [Embedded Systems](<https://devfeed.tech/topics/embedded-systems.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [simulator](<https://devfeed.tech/topics/simulator.md>), [developer tooling](<https://devfeed.tech/topics/developer-tooling.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [blog](<https://devfeed.tech/tags/blog.md>), [bugs](<https://devfeed.tech/tags/bugs.md>), [community](<https://devfeed.tech/tags/community.md>), [contributors](<https://devfeed.tech/tags/contributors.md>), [embedded](<https://devfeed.tech/tags/embedded.md>), [embedded-systems](<https://devfeed.tech/tags/embedded-systems.md>), [event](<https://devfeed.tech/tags/event.md>), [events](<https://devfeed.tech/tags/events.md>), [firmware](<https://devfeed.tech/tags/firmware.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [harness](<https://devfeed.tech/tags/harness.md>), [meetup](<https://devfeed.tech/tags/meetup.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [simulator](<https://devfeed.tech/tags/simulator.md>), [talk](<https://devfeed.tech/tags/talk.md>), [technologies](<https://devfeed.tech/tags/technologies.md>), [tooling](<https://devfeed.tech/tags/tooling.md>), [tools](<https://devfeed.tech/tags/tools.md>), [zephyr](<https://devfeed.tech/tags/zephyr.md>)

### AI overview

The Zephyr Project Meetup in Amsterdam on September 15, 2026, will bring together embedded developers, contributors, students, and engineers to exchange practical knowledge about Zephyr RTOS. The agenda includes talks on JetBrains' work with Zephyr, fuzzing Zephyr applications with AFL and Renode, and making hardware development easier with Schematik.

### Source excerpt

What are developers in the Netherlands building with Zephyr? On September 15, the embedded community will meet in Amsterdam to exchange practical knowledge, discuss current work, and learn more about the Zephyr RTOS. The event is open to experienced contributors, first-time users, students, engineers, and anyone curious about open source embedded development.

## What to expect at the Zephyr Project Meetup (September 15, 2026) - Amsterdam, Netherlands

DevFeed: [What to expect at the Zephyr Project Meetup (September 15, 2026) - Amsterdam, Netherlands](<https://devfeed.tech/articles/what-to-expect-at-the-zephyr-project-meetup-september-15-2026-amsterdam-netherlands-38677.md>)

Original publisher: [Read original article](<https://zephyrproject.org/what-to-expect-at-the-zephyr-project-meetup-september-15-2026-amsterdam-netherlands/>)

Author: Susan Remmert

Published: 2026-09-09T05:00:04Z

Content type: news

Language: en

Sources: [Zephyr Project](<https://devfeed.tech/sources/zephyr-project-2.md>)

Topics: [Zephyr RTOS](<https://devfeed.tech/topics/zephyr-rtos.md>), [Embedded Systems](<https://devfeed.tech/topics/embedded-systems.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [blog](<https://devfeed.tech/tags/blog.md>), [c](<https://devfeed.tech/tags/c.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [crashes](<https://devfeed.tech/tags/crashes.md>), [developer-tooling](<https://devfeed.tech/tags/developer-tooling.md>), [embedded](<https://devfeed.tech/tags/embedded.md>), [embedded-systems](<https://devfeed.tech/tags/embedded-systems.md>), [event](<https://devfeed.tech/tags/event.md>), [events](<https://devfeed.tech/tags/events.md>), [firmware](<https://devfeed.tech/tags/firmware.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [harness](<https://devfeed.tech/tags/harness.md>), [jetbrains](<https://devfeed.tech/tags/jetbrains.md>), [meetup](<https://devfeed.tech/tags/meetup.md>), [memory-corruption](<https://devfeed.tech/tags/memory-corruption.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [simulator](<https://devfeed.tech/tags/simulator.md>), [zephyr](<https://devfeed.tech/tags/zephyr.md>)

### AI overview

The Zephyr Project Meetup in Amsterdam on September 15, 2026, will bring together embedded developers, contributors, students, and engineers to share practical knowledge about Zephyr RTOS. The agenda includes talks on JetBrains' work with Zephyr, fuzzing Zephyr with AFL and Renode, and making hardware development easier with Schematik.

### Source excerpt

What are developers in the Netherlands building with Zephyr? On September 15, the embedded community will meet in Amsterdam to exchange practical knowledge, discuss current work, and learn more about the Zephyr RTOS. The event is open to experienced contributors, first-time users, students, engineers, and anyone curious about open source embedded development.

## Stronger with every update: How we're making Chrome and the web safer in the AI Era

DevFeed: [Stronger with every update: How we're making Chrome and the web safer in the AI Era](<https://devfeed.tech/articles/stronger-with-every-update-how-we-re-making-chrome-and-the-web-safer-in-the-ai-era-7623.md>)

Original publisher: [Read original article](<https://blog.google/security/chrome-stronger-with-every-update/>)

Author: Chrome Security Team

Published: 2026-07-30T17:00:00Z

Content type: article

Language: en

Sources: [Security](<https://devfeed.tech/sources/security.md>)

Topics: [Chrome](<https://devfeed.tech/topics/chrome.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Agent Harness](<https://devfeed.tech/topics/agent-harness.md>), [V8](<https://devfeed.tech/topics/v8.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [interoperability](<https://devfeed.tech/topics/interoperability.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-models](<https://devfeed.tech/tags/ai-models.md>), [bug](<https://devfeed.tech/tags/bug.md>), [bugs](<https://devfeed.tech/tags/bugs.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [chrome-security](<https://devfeed.tech/tags/chrome-security.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [interoperability](<https://devfeed.tech/tags/interoperability.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [none](<https://devfeed.tech/tags/none.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article describes how Chrome's security teams use large language models, fuzzing, specialized research tools, and AI vulnerability-discovery agents to find and remediate security bugs more quickly. It highlights Big Sleep, an agent harness using Gemini, model interoperability, and a Chrome knowledge base built from CVEs and Git history.

### Source excerpt

Video of Chrome logo turning into a shield

## Introducing Patch the Planet

DevFeed: [Introducing Patch the Planet](<https://devfeed.tech/articles/introducing-patch-the-planet-7654.md>)

Original publisher: [Read original article](<https://blog.trailofbits.com/2026/06/22/introducing-patch-the-planet/>)

Author: "Trail of Bits"

Published: 2026-06-22T16:50:00Z

Content type: article

Language: en

Sources: [The Trail of Bits Blog](<https://devfeed.tech/sources/the-trail-of-bits-blog.md>), [The Trail of Bits Blog](<https://devfeed.tech/sources/the-trail-of-bits-blog-2.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [pull-requests](<https://devfeed.tech/topics/pull-requests.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [networking](<https://devfeed.tech/topics/networking.md>), [cURL](<https://devfeed.tech/topics/curl.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>)

Tags: [announcements](<https://devfeed.tech/tags/announcements.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [go](<https://devfeed.tech/tags/go.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [networking](<https://devfeed.tech/tags/networking.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openai](<https://devfeed.tech/tags/openai.md>), [patch-the-planet](<https://devfeed.tech/tags/patch-the-planet.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Patch the Planet pairs Trail of Bits engineers and open-source maintainers with frontier models to discover, triage, and fix security issues. Its first week produced hundreds of bugs, 64 pull requests, and 51 issues across 19 projects, with work also adding tests, fuzzing harnesses, CI security scanning, supply-chain tooling, correctness fixes, and features.

### Source excerpt

What happens when you clear dozens of Trail of Bits engineers' schedules, pair them with every open-source maintainer they can contact, and unleash the latest frontier models like GPT-5.5-Cyber on critical open-source targets? Thanks to our partnership with OpenAI and its Daybreak initiative, we can report that the impact is hundreds of discovered bugs, 64 pull requests, and 51 issues filed across 19 projects (with many more still undergoing coordinated disclosure). That was just the first week of Patch the Planet. Frontier models like GPT-5.5-Cyber are producing a firehose of security findings, and already-stretched maintainers must sift through all of it to separate real vulnerabilities from plausible-sounding false positives. Patch the Planet is different: with our experts orchestrating and triaging findings, we handle the work of fixing and hardening the code alongside the people who maintain it. The first week of Patch the Planet covered 19 projects across cryptography, networking, language infrastructure, and software supply chain. Among these 19 projects were cURL, NATS, pyca, Sigstore, aiohttp, the Go project, freenginx, Python and python.org, urllib3, PyPI, SimpleX, Valkey, and RustCrypto. Over 30 projects have joined the initiative so far, and we're rapidly expanding it to include more; if you maintain an open-source project, apply to join! Live look at the Trail of Bits engineering teams Anyone can file an issue, flex, and walk away. We showed up with the patches: 37 are already merged, and many more are in flight. These merges go beyond just fixing bugs: we're adding new tests and fuzzing harnesses, CI security scanning, supply-chain tooling, correctness fixes, and features maintainers had been meaning to get to. The goal of Patch the Planet is to leave essential open-source projects measurably better off. We brought patches, not just bug reports We're reporting public findings on GitHub, including 64 total pull requests. We also filed 51 issues, 19 of w

## Choosing Values for Robust Tests

DevFeed: [Choosing Values for Robust Tests](<https://devfeed.tech/articles/choosing-values-for-robust-tests-23871.md>)

Original publisher: [Read original article](<http://testing.googleblog.com/2026/06/choosing-values-for-robust-tests.html>)

Author: Google Testing Bloggers (noreply@blogger.com)

Published: 2026-06-04T12:47:00Z

Content type: tutorial

Language: en

Sources: [Google Testing Blog](<https://devfeed.tech/sources/google-testing-blog.md>)

Topics: [Testing](<https://devfeed.tech/topics/testing.md>), [test](<https://devfeed.tech/topics/test.md>), [Code](<https://devfeed.tech/topics/code.md>), [implementation](<https://devfeed.tech/topics/implementation.md>), [bug](<https://devfeed.tech/topics/bug.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [bug](<https://devfeed.tech/tags/bug.md>), [code](<https://devfeed.tech/tags/code.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [implementation](<https://devfeed.tech/tags/implementation.md>), [radion-khait](<https://devfeed.tech/tags/radion-khait.md>), [test](<https://devfeed.tech/tags/test.md>), [testing](<https://devfeed.tech/tags/testing.md>), [tests](<https://devfeed.tech/tags/tests.md>), [tott](<https://devfeed.tech/tags/tott.md>), [unit-test](<https://devfeed.tech/tags/unit-test.md>)

### AI overview

The article explains how default-valued test inputs can let broken implementations pass unnoticed. It recommends non-default values, varied scenarios, boundary and special-case inputs, fuzzing, and distinct values for each parameter to improve test coverage and confidence.

### Source excerpt

This article was adapted from a Google Tech on the Toilet (TotT) episode. You can download a printer-friendly version of this TotT episode and post it in your office. By Radion Khait A test passes. Great! But does it really mean your code is working as expected? Not necessarily.Sometimes the values you choose in your tests can create a false sense of security, especially when dealing with default values. Consider this snippet of a simple map class and its corresponding unit test: Implementation Test void MyMap::insert(int key, int value) { // Oops! The map entry is default-initialized, // the second parameter is not used. internal_map_[key]; } TEST(MyMapTest, Insert) { MyMap my_map; my_map.insert(1, 0); // This passes! EXPECT_EQ(my_map.get(1), 0); } The test passes, but the insert method is broken! It never actually stores the value. The test only passes because the default value for an integer in the map (0) happens to match the value used in the test. When choosing test values, consider the following: Test with non-default values. Explicitly test with values different from the type's default (e.g., non-zero numbers, non-empty strings, enum values other than the one at index 0). This provides greater confidence that your code is actually using the provided input. TEST(MyMapTest, Insert) { MyMap my_map; my_map.insert(1, 5); // This test would fail and reveal the bug in // the implementation above: "Expected 5, got 0". EXPECT_EQ(my_map.get(1), 5); } Test multiple inputs that cover different scenarios, where it is reasonable to do so. Consider empty/missing/null values, numerical boundaries, and special cases that trigger complex logic. Try to cover all distinct code/logic paths. Consider using fuzzing to more thoroughly cover the input domain. Use different values for each input. This guarantees the code under test doesn't accidentally reuse a single input or switch their order. Parameterized testing can also help test a large variety of inputs with minimal code dupl

## New Logic for Programmers (and the future of this newsletter)

DevFeed: [New Logic for Programmers (and the future of this newsletter)](<https://devfeed.tech/articles/new-logic-for-programmers-and-the-future-of-this-newsletter-25497.md>)

Original publisher: [Read original article](<https://buttondown.com/hillelwayne/archive/new-logic-for-programmers-and-the-future-of-this/>)

Author: Hillel Wayne

Published: 2026-05-06T17:03:46Z

Content type: opinion

Language: en

Sources: [Newsletter feed for Hillel Wayne's Newsletter](<https://devfeed.tech/sources/newsletter-feed-for-hillel-wayne-s-newsletter.md>)

Topics: [Formal methods](<https://devfeed.tech/topics/formal-methods.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Programming](<https://devfeed.tech/topics/programming.md>)

Tags: [developer](<https://devfeed.tech/tags/developer.md>), [formal-methods](<https://devfeed.tech/tags/formal-methods.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [newsletter](<https://devfeed.tech/tags/newsletter.md>), [release](<https://devfeed.tech/tags/release.md>), [testing](<https://devfeed.tech/tags/testing.md>), [updates](<https://devfeed.tech/tags/updates.md>)

### AI overview

The author announces version 0.14 of Logic for Programmers, reports progress toward a 1.0 print edition, and shares plans to join Antithesis as a developer educator. The newsletter may shift toward software history and related topics, with its future publishing frequency uncertain.

### Source excerpt

So first the immediate news: I just released version 0.14 of Logic for Programmers! This release is pretty similar to 0.13. There are a few rewrites but the vast majority of the changes are layout, copyediting, and technical editing. Full notes here. In related news, I've started doing test prints of the book: There's not a whole lot left to be done. I've gotta fix up some diagrams, do more formatting and proofreading, incorporate some fixes raised by readers, and make a website and back cover. After that, the book should be ready for 1.0. I'm aiming to have print copies purchasable by the end of June! Now the big news: starting August, I'll be a full-time employee of Antithesis, a generative testing platform. Officially my role is "developer educator", and I'll be tasked with making "property-based testing, fuzzing, fault injection, Hegel, Bombadil, and the Antithesis platform understandable to everyday engineers". So the same kind of work I do now, except with far more support and a matching 401(k). I already have three pages of topic ideas you have no idea how excited I am about this So how is this going to affect the newsletter? First, I want to make clear that this is not going to become an Antithesis newsletter. My Antithesis-related work is going to be on their official platforms. I do think one of the best ways to make a topic "understandable" is to write foundational material that's useful to all engineers, whether they're invested in the topic or not. I might share links to things I make along those lines, but they'll be just that, links. At the same time, the content of this newsletter will change a little. Property testing and fuzzing aren't the same as formal methods, but a lot of the foundations overlap, especially in how we think about properties and correctness. I don't know for sure yet, but I suspect that I'll start biasing this newsletter away from Antithesis related topics. So there will probably be less theoretic things like what does undecidabl

## Extending Ruzzy with LibAFL

DevFeed: [Extending Ruzzy with LibAFL](<https://devfeed.tech/articles/extending-ruzzy-with-libafl-7648.md>)

Original publisher: [Read original article](<https://blog.trailofbits.com/2026/04/29/extending-ruzzy-with-libafl/>)

Author: "Matt Schwager"

Published: 2026-04-29T11:00:00Z

Content type: article

Language: en

Sources: [The Trail of Bits Blog](<https://devfeed.tech/sources/the-trail-of-bits-blog.md>), [The Trail of Bits Blog](<https://devfeed.tech/sources/the-trail-of-bits-blog-2.md>)

Topics: [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Ruby](<https://devfeed.tech/topics/ruby.md>), [Rust](<https://devfeed.tech/topics/rust.md>), [LLVM](<https://devfeed.tech/topics/llvm.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [complex-systems](<https://devfeed.tech/tags/complex-systems.md>), [developers](<https://devfeed.tech/tags/developers.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [linux](<https://devfeed.tech/tags/linux.md>), [llvm](<https://devfeed.tech/tags/llvm.md>), [ruby](<https://devfeed.tech/tags/ruby.md>), [rust](<https://devfeed.tech/tags/rust.md>), [tool-release](<https://devfeed.tech/tags/tool-release.md>), [tools](<https://devfeed.tech/tags/tools.md>)

### AI overview

The article describes adding LibAFL support to Ruzzy, a coverage-guided fuzzer for pure Ruby code and Ruby C extensions. It covers building LibAFL as a standalone library, integrating it through a Dockerfile, and investigating ELF and linker issues encountered during the integration.

### Source excerpt

LibAFL is all the rage in the fuzzing community these days, especially with LLVM's libFuzzer being placed in maintenance mode. Written in Rust, LibAFL claims improved performance, modularity, state-of-the-art fuzzing techniques, and libFuzzer compatibility. For these reasons, I set out to add LibAFL support to Ruzzy, our coverage-guided fuzzer for pure Ruby code and Ruby C extensions. This gives Ruby developers and security researchers access to a more advanced and actively maintained fuzzing engine without changing how they write their fuzzing harnesses. Ruzzy was originally built on top of LLVM's libFuzzer, so using LibAFL's compatibility layer should be easy enough. However, digging around in the internals of complex systems is never quite as simple as it seems. In this post, I will investigate some of the deep plumbing inside these fuzzing engines, take a detour into executable and linkable format (ELF) files, and ultimately add LibAFL support to Ruzzy. Building with libafl_libfuzzer Ruzzy currently supports Linux, so I use a Dockerfile for development and for production fuzzing campaigns. To that end, using a similar Dockerfile for LibAFL support is the simplest integration point. LibAFL provides excellent documentation and build scripts to use it as a standalone library. We need to build LibAFL as a standalone library because Ruzzy uses libFuzzer as a library. Following along with the standalone libafl_libfuzzer documentation, and with the build.sh script in hand, we can build libFuzzer.a. This is the archive that will ultimately be linked into Ruzzy's C extension and used to fuzz our target. Here are the relevant lines from our new Dockerfile: # Install Rust nightly via rustup RUN wget -qO- https://sh.rustup.rs | sh -s -- \ -y \ --default-toolchain nightly \ --component llvm-tools ENV PATH="/root/.cargo/bin:${PATH}" # Clone LibAFL RUN git clone --depth 1 https://github.com/AFLplusplus/LibAFL /libafl # Build libFuzzer.a from LibAFL's libfuzzer runtime WORKDIR

## Introduction to Fuzzing ESP-IDF components

DevFeed: [Introduction to Fuzzing ESP-IDF components](<https://devfeed.tech/articles/introduction-to-fuzzing-esp-idf-components-13743.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/2026/01/fuzzing/>)

Author: John Lee

Published: 2026-01-07T00:00:00Z

Content type: tutorial

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [ESP-IDF](<https://devfeed.tech/topics/esp-idf.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [c/c++](<https://devfeed.tech/topics/c-c-plus-plus.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [c-c-plus-plus](<https://devfeed.tech/tags/c-c-plus-plus.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [component](<https://devfeed.tech/tags/component.md>), [embedded](<https://devfeed.tech/tags/embedded.md>), [esp-idf](<https://devfeed.tech/tags/esp-idf.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This article introduces fuzzing for ESP-IDF components and embedded libraries. It explains how to fuzz host-compiled code with sanitizers, compares black-box, grey-box, and white-box approaches, and outlines workflows using a basic mutator, AFL++, and protocol-focused harnesses.

### Source excerpt

This article introduces fuzzing -- a technique for finding vulnerabilities -- and demonstrates practical workflows and lessons learned for ESP-IDF components and embedded libraries in general.

## exploits.club Weekly Newsletter 90 - Fuzzing Rust Subsystems, Pwn2Own Near Misses, Linux 1-Days, And More

DevFeed: [exploits.club Weekly Newsletter 90 - Fuzzing Rust Subsystems, Pwn2Own Near Misses, Linux 1-Days, And More](<https://devfeed.tech/articles/exploits-club-weekly-newsletter-90-fuzzing-rust-subsystems-pwn2own-near-misses-linux-1-days-and-more-32647.md>)

Original publisher: [Read original article](<https://blog.exploits.club/exploits-club-weekly-newsletter-90-fuzzing-rust-subsystems-pwn2own-near-misses-linux-1-days-and-more/>)

Author: exploits.club

Published: 2025-10-23T17:00:02Z

Content type: news

Language: en

Sources: [exploits.club](<https://devfeed.tech/sources/exploits-club.md>)

Topics: [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Rust](<https://devfeed.tech/topics/rust.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Security](<https://devfeed.tech/topics/security.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [network security](<https://devfeed.tech/topics/network-security.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [Parsing](<https://devfeed.tech/topics/parsing.md>)

Tags: [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux](<https://devfeed.tech/tags/linux.md>), [network-security](<https://devfeed.tech/tags/network-security.md>), [parsing](<https://devfeed.tech/tags/parsing.md>), [rce](<https://devfeed.tech/tags/rce.md>), [rust](<https://devfeed.tech/tags/rust.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This weekly newsletter rounds up security research and developer-related resources, including fuzzing of Rust code in the Windows kernel, a WatchGuard Fireware OS vulnerability analysis, and a near-miss Pwn2Own printer exploit write-up.

### Source excerpt

Good thing that absolutely no drama whatsoever took place for US vuln research firms this week...annnnnyways 👇 In Case You Missed It... OffensiveCon CFP - Closes March 1st, 2026 so let the procrastination begin! RE//Verse CFP - These need to be in by November 14th, so a bit less procrastinating.

## Trace similarity systems on top of ClickHouse to analyze crash stack traces from our CI

DevFeed: [Trace similarity systems on top of ClickHouse to analyze crash stack traces from our CI](<https://devfeed.tech/articles/trace-similarity-systems-on-top-of-clickhouse-to-analyze-crash-stack-traces-from-our-ci-5607.md>)

Original publisher: [Read original article](<https://clickhouse.com/blog/trace-similarity-stack-traces>)

Author: Misha Shiryaev

Published: 2025-09-24T12:46:35Z

Content type: article

Language: en

Sources: [ClickHouse Blog](<https://devfeed.tech/sources/clickhouse-blog.md>)

Topics: [clickhouse](<https://devfeed.tech/topics/clickhouse.md>), [ci](<https://devfeed.tech/topics/ci.md>), [Traces](<https://devfeed.tech/topics/traces.md>), [issue tracker](<https://devfeed.tech/topics/issue-tracker.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [FIRST](<https://devfeed.tech/topics/first.md>)

Tags: [ci](<https://devfeed.tech/tags/ci.md>), [clickhouse](<https://devfeed.tech/tags/clickhouse.md>), [crash-reporting](<https://devfeed.tech/tags/crash-reporting.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [github](<https://devfeed.tech/tags/github.md>), [issue-tracker](<https://devfeed.tech/tags/issue-tracker.md>), [logs](<https://devfeed.tech/tags/logs.md>), [trace](<https://devfeed.tech/tags/trace.md>)

### AI overview

This article explains how to build a trace similarity system on top of ClickHouse to analyze crash stack traces from CI. It describes collecting crash reports, extracting stack frames, grouping similar traces, and creating or updating GitHub issues so teams can distinguish new bugs from known ones.

### Source excerpt

Learn how our engineering team cut through noisy CI crash reports with a trace similarity system built on ClickHouse.

## exploits.club Weekly Newsletter 85 -Fuzzing KSMBD, Kernel-Hack-Drill, Vibe-Crashing, And More

DevFeed: [exploits.club Weekly Newsletter 85 -Fuzzing KSMBD, Kernel-Hack-Drill, Vibe-Crashing, And More](<https://devfeed.tech/articles/exploits-club-weekly-newsletter-85-fuzzing-ksmbd-kernel-hack-drill-vibe-crashing-and-more-32642.md>)

Original publisher: [Read original article](<https://blog.exploits.club/exploits-club-weekly-newsletter-85-fuzzing-ksmbd-kernel-hack-drill-vibe-crashing-and-more/>)

Author: exploits.club

Published: 2025-09-04T15:00:32Z

Content type: article

Language: en

Sources: [exploits.club](<https://devfeed.tech/sources/exploits-club.md>)

Topics: [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Linux Kernel](<https://devfeed.tech/topics/linux-kernel.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Security](<https://devfeed.tech/topics/security.md>), [race-condition](<https://devfeed.tech/topics/race-condition.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Ubuntu](<https://devfeed.tech/topics/ubuntu.md>)

Tags: [exploits](<https://devfeed.tech/tags/exploits.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux-kernel](<https://devfeed.tech/tags/linux-kernel.md>), [race-condition](<https://devfeed.tech/tags/race-condition.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The 85th exploits.club weekly newsletter highlights work on fuzzing improvements and vulnerability discovery in ksmbd, including 23 reported bugs. It also covers Kernel-Hack-Drill research on exploiting CVE-2024-50264, a Linux kernel socket race condition resulting in use-after-free, and related exploitation constraints.

### Source excerpt

New idea - let AI submit a different, buzzwordy talks to every CFP. What could go wrong? Annnnnnnnyways 👇 In Case You Missed It... 0-day Hunting Strategy with Eugene "Spaceraccoon" Lim - Following the release of his recent No Starch Press book, @spaceraccoonsec will be on tomorrow'

## exploits.club Weekly Newsletter 80 - ITW Windows Bugs, Deterministic iOS Exploits, Pwn2Own Firefox Vulns, and More

DevFeed: [exploits.club Weekly Newsletter 80 - ITW Windows Bugs, Deterministic iOS Exploits, Pwn2Own Firefox Vulns, and More](<https://devfeed.tech/articles/exploits-club-weekly-newsletter-80-itw-windows-bugs-deterministic-ios-exploits-pwn2own-firefox-vulns-and-more-32637.md>)

Original publisher: [Read original article](<https://blog.exploits.club/exploits-club-weekly-newsletter-80-itw-windows-bugs-deterministic-ios-exploits-pwn2own-firefox-vulns-and-more/>)

Author: exploits.club

Published: 2025-07-24T15:21:15Z

Content type: news

Language: en

Sources: [exploits.club](<https://devfeed.tech/sources/exploits-club.md>)

Topics: [iOS](<https://devfeed.tech/topics/ios.md>), [Firefox](<https://devfeed.tech/topics/firefox.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [bug](<https://devfeed.tech/topics/bug.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [IO](<https://devfeed.tech/topics/io.md>), [Mozilla](<https://devfeed.tech/topics/mozilla.md>)

Tags: [bugs](<https://devfeed.tech/tags/bugs.md>), [cve](<https://devfeed.tech/tags/cve.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [firefox](<https://devfeed.tech/tags/firefox.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [ios](<https://devfeed.tech/tags/ios.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [love](<https://devfeed.tech/tags/love.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

This issue of exploits.club Weekly Newsletter reviews recent security research and resources, including white-box fuzzing with AFL++, deterministic iOS kernel exploits extended to additional chipsets, an analysis of the Windows vulnerability CVE-2025-29824 and its use in the wild, and a Mozilla Firefox vulnerability discussed in connection with Pwn2Own.

### Source excerpt

The Cameraman at that Coldplay concert pic.twitter.com/MHtqBxbwC6 -- Hater Report (@HaterReport_) July 18, 2025 Annnnnnnyways 👇 80 NEWSLETTERS 🎉 In Case You Missed It... Fuzzing 1001: Introductory white-box fuzzing with AFL++ - new course from OST2! Pwnie Nominees for 2025 - Released this week. Check them out!! Resources

## Xen Project 4.20: A Step Forward in Open Source Virtualization

DevFeed: [Xen Project 4.20: A Step Forward in Open Source Virtualization](<https://devfeed.tech/articles/xen-project-4-20-a-step-forward-in-open-source-virtualization-12838.md>)

Original publisher: [Read original article](<https://xenproject.org/blog/xen-project-4-20-oss-virtualization/>)

Author: Cody Zuschlag

Published: 2025-03-11T13:30:38Z

Content type: article

Language: en

Sources: [Blog - Xen Project](<https://devfeed.tech/sources/blog-xen-project.md>)

Topics: [virtualization](<https://devfeed.tech/topics/virtualization.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Optimization](<https://devfeed.tech/topics/optimization.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [amd](<https://devfeed.tech/tags/amd.md>), [announcements](<https://devfeed.tech/tags/announcements.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [intel](<https://devfeed.tech/tags/intel.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [optimization](<https://devfeed.tech/tags/optimization.md>), [performance](<https://devfeed.tech/tags/performance.md>), [release](<https://devfeed.tech/tags/release.md>), [releases](<https://devfeed.tech/tags/releases.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [virtualization](<https://devfeed.tech/tags/virtualization.md>), [xen-4-20](<https://devfeed.tech/tags/xen-4-20.md>)

### AI overview

The article discusses the Xen Project's Xen 4.20 release as an open-source virtualization update. It highlights security improvements, including expanded MISRA C compliance, fuzzing, and UBSAN enabled by default, along with performance optimizations for page-table management, cache utilization, device passthrough, Intel CPUs, and AMD Zen 5. The release is presented as targeting cloud, enterprise, and embedded-system workloads.

### Source excerpt

Xen 4.20 is here! 🚀 This release boosts security, performance, and architecture support, shaping the future of open-source virtualization.

## ClickHouse at FOSDEM 2025: talks, tech, and a community dinner

DevFeed: [ClickHouse at FOSDEM 2025: talks, tech, and a community dinner](<https://devfeed.tech/articles/clickhouse-at-fosdem-2025-talks-tech-and-a-community-dinner-5071.md>)

Original publisher: [Read original article](<https://clickhouse.com/blog/clickhouse-at-fosdem-2025>)

Author: Tyler Hannan

Published: 2025-02-25T15:08:26Z

Content type: article

Language: en

Sources: [ClickHouse Blog](<https://devfeed.tech/sources/clickhouse-blog.md>)

Topics: [clickhouse](<https://devfeed.tech/topics/clickhouse.md>), [JSON](<https://devfeed.tech/topics/json.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [clickhouse](<https://devfeed.tech/tags/clickhouse.md>), [community](<https://devfeed.tech/tags/community.md>), [databases](<https://devfeed.tech/tags/databases.md>), [deep-dive](<https://devfeed.tech/tags/deep-dive.md>), [developers](<https://devfeed.tech/tags/developers.md>), [fosdem](<https://devfeed.tech/tags/fosdem.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [json](<https://devfeed.tech/tags/json.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [tech](<https://devfeed.tech/tags/tech.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

A recap of ClickHouse's presence at FOSDEM 2025, covering a talk on its new powerful JSON data type and another on the challenges of fuzzing databases. The JSON presentation discusses column-oriented storage, dynamically changing structures, and fast querying of individual JSON paths.

### Source excerpt

This year, ClickHouse made a strong showing at FOSDEM 2025, with several team members traveling to Belgium and multiple talks covering everything from powerful new JSON data types to the challenges of fuzzing databases.

## Concealing payloads in URL credentials

DevFeed: [Concealing payloads in URL credentials](<https://devfeed.tech/articles/concealing-payloads-in-url-credentials-7671.md>)

Original publisher: [Read original article](<https://portswigger.net/research/concealing-payloads-in-url-credentials>)

Author: Gareth Heyes

Published: 2024-10-23T12:59:05Z

Content type: article

Language: en

Sources: [PortSwigger Research](<https://devfeed.tech/sources/portswigger-research.md>)

Topics: [payload](<https://devfeed.tech/topics/payload.md>), [browsers](<https://devfeed.tech/topics/browsers.md>), [Chrome](<https://devfeed.tech/topics/chrome.md>), [Firefox](<https://devfeed.tech/topics/firefox.md>), [Document Object Model (DOM)](<https://devfeed.tech/topics/dom.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Redirection](<https://devfeed.tech/topics/redirection.md>)

Tags: [browsers](<https://devfeed.tech/tags/browsers.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [firefox](<https://devfeed.tech/tags/firefox.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [payload](<https://devfeed.tech/tags/payload.md>), [redirection](<https://devfeed.tech/tags/redirection.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains how payloads can be concealed in the credentials portion of URLs while remaining hidden from the address bars of Chrome and Firefox. It examines differences between document.URL and location, Firefox's handling of single quotes, and applications to DOM XSS, anchor credentials, redirection, and DOM clobbering. Safari discards URL credentials, so the described examples work only in Chrome and Firefox.

### Source excerpt

Last year Johan Carlsson discovered you could conceal payloads inside the credentials part of the URL . This was fascinating to me especially because the payload is not actually visible in the URL in

## FuzzSlice: Separating real CVEs from fakes through fuzzing

DevFeed: [FuzzSlice: Separating real CVEs from fakes through fuzzing](<https://devfeed.tech/articles/fuzzslice-separating-real-cves-from-fakes-through-fuzzing-13055.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/fuzzslice-separating-real-cves-from-fakes-through-fuzzing>)

Published: 2024-09-19T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [Security](<https://devfeed.tech/topics/security.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>)

Tags: [cves](<https://devfeed.tech/tags/cves.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

Chainguard Labs presents FuzzSlice, a fuzzing technique for determining whether CVEs are exploitable within an application context. In an evaluation of 18 OpenSSL CVEs, it classified 12 as exploitable and six as unreachable or false positives.

### Source excerpt

Chainguard Labs explores FuzzSlice, a novel fuzzing technique, to improve vulnerability remediation by distinguishing exploitable CVEs from false positives.

## Introducing Bettercap 2.4.0: CAN-Bus Hacking, WiFi Bruteforcing and Builtin Web UI

DevFeed: [Introducing Bettercap 2.4.0: CAN-Bus Hacking, WiFi Bruteforcing and Builtin Web UI](<https://devfeed.tech/articles/introducing-bettercap-2-4-0-can-bus-hacking-wifi-bruteforcing-and-builtin-web-ui-41269.md>)

Original publisher: [Read original article](<https://www.evilsocket.net/2024/09/13/Introducing-bettercap-2-4-0-CAN-bus-hacking-WiFi-bruteforcing-and-builtin-web-UI/>)

Author: Simone Margaritelli

Published: 2024-09-13T10:46:25Z

Content type: release

Language: en

Sources: [evilsocket](<https://devfeed.tech/sources/evilsocket.md>)

Topics: [Hacking](<https://devfeed.tech/topics/hacking.md>), [Security](<https://devfeed.tech/topics/security.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>), [ui](<https://devfeed.tech/topics/ui.md>)

Tags: [automotive-security](<https://devfeed.tech/tags/automotive-security.md>), [bettercap](<https://devfeed.tech/tags/bettercap.md>), [can-bus](<https://devfeed.tech/tags/can-bus.md>), [canbus](<https://devfeed.tech/tags/canbus.md>), [car](<https://devfeed.tech/tags/car.md>), [car-hacking](<https://devfeed.tech/tags/car-hacking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [features](<https://devfeed.tech/tags/features.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [ics](<https://devfeed.tech/tags/ics.md>), [industrial](<https://devfeed.tech/tags/industrial.md>), [industrial-control](<https://devfeed.tech/tags/industrial-control.md>), [offensive-tools](<https://devfeed.tech/tags/offensive-tools.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [release](<https://devfeed.tech/tags/release.md>), [socketcan](<https://devfeed.tech/tags/socketcan.md>), [webui](<https://devfeed.tech/tags/webui.md>), [wifi](<https://devfeed.tech/tags/wifi.md>), [wifi-bruteforcing](<https://devfeed.tech/tags/wifi-bruteforcing.md>), [wireless-security](<https://devfeed.tech/tags/wireless-security.md>)

### AI overview

The article announces bettercap 2.4.0, a major release that adds functionality for car and industrial control system security research. It describes a new CAN-bus module for reading, replaying, injecting, and fuzzing frames, parsing frames with DBC files, and detecting ECUs, alongside other new features and fixes.

### Source excerpt

I'm happy to announce, after quite some time, the new bettercap 2.4.0 major release. Other than including a plethora of long due fixes (additionally to what the recent 2.33.0 already fixed), it also packs a few new functionalities that extend its reach to car and industrial control system hacking. It'll possibly take me some time to update the documentation on the official website so I'm here today to write a bit about the new features. Also remember that you can use the help, help ui, help can and help wifi commands to check all the new options and added functionalities.

## Mastering Nixpkgs Overlays: Techniques and Best Practice

DevFeed: [Mastering Nixpkgs Overlays: Techniques and Best Practice](<https://devfeed.tech/articles/mastering-nixpkgs-overlays-techniques-and-best-practice-32438.md>)

Original publisher: [Read original article](<https://nixcademy.com/posts/mastering-nixpkgs-overlays-techniques-and-best-practice/>)

Author: Jacek Galowicz

Published: 2024-08-01T00:00:00Z

Content type: tutorial

Language: en

Sources: [Nixcademy Blog](<https://devfeed.tech/sources/nixcademy-blog.md>)

Topics: [Nix](<https://devfeed.tech/topics/nix.md>), [function](<https://devfeed.tech/topics/function.md>), [monorepo](<https://devfeed.tech/topics/monorepo.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [systems](<https://devfeed.tech/topics/systems.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Testing](<https://devfeed.tech/topics/testing.md>)

Tags: [function](<https://devfeed.tech/tags/function.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [monorepo](<https://devfeed.tech/tags/monorepo.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [patches](<https://devfeed.tech/tags/patches.md>), [systems](<https://devfeed.tech/tags/systems.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

This tutorial explains how Nixpkgs overlays help compose package collections and build different package or system-image variants. It covers the problems overlays solve, how to apply them to package trees and system images, and positive and negative examples.

### Source excerpt

Overlays in Nixpkgs are a powerful mechanism, but they are also complex to grasp. We tell you everything you need to know about Nixpkgs overlays.

## Snapshots for IPC Fuzzing

DevFeed: [Snapshots for IPC Fuzzing](<https://devfeed.tech/articles/snapshots-for-ipc-fuzzing-4130.md>)

Original publisher: [Read original article](<https://hacks.mozilla.org/2024/06/snapshots-for-ipc-fuzzing/>)

Author: Christian Holler

Published: 2024-06-27T16:18:49Z

Content type: article

Language: en

Sources: [Mozilla Hacks - the Web developer blog](<https://devfeed.tech/sources/mozilla-hacks-the-web-developer-blog.md>)

Topics: [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Firefox](<https://devfeed.tech/topics/firefox.md>), [out-of-process](<https://devfeed.tech/topics/out-of-process.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Testing](<https://devfeed.tech/topics/testing.md>)

Tags: [featured-article](<https://devfeed.tech/tags/featured-article.md>), [firefox](<https://devfeed.tech/tags/firefox.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [ipc](<https://devfeed.tech/tags/ipc.md>), [memory-safety](<https://devfeed.tech/tags/memory-safety.md>), [mozilla](<https://devfeed.tech/tags/mozilla.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [processes](<https://devfeed.tech/tags/processes.md>), [security](<https://devfeed.tech/tags/security.md>), [snapshots](<https://devfeed.tech/tags/snapshots.md>), [ssecurity](<https://devfeed.tech/tags/ssecurity.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains how Firefox uses process separation and IPC to isolate lower-privilege content processes from the privileged parent process. It introduces snapshot fuzzing, a method for rewinding application state to make testing critical IPC interfaces more practical by avoiding costly browser restarts and reducing iteration latency.

### Source excerpt

Process separation remains one of the most important parts of the Firefox security model and securing our IPC (Inter-Process Communication) interfaces is crucial to keep privileges in the different processes separated. We take a more detailed look at our newest tool for finding vulnerabilities in these interfaces - snapshot fuzzing. The post Snapshots for IPC Fuzzing appeared first on Mozilla Hacks - the Web developer blog.

## Secured #6 - Writing Robust C - Best Practices for Finding and Preventing Vulnerabilities

DevFeed: [Secured #6 - Writing Robust C - Best Practices for Finding and Preventing Vulnerabilities](<https://devfeed.tech/articles/secured-6-writing-robust-c-best-practices-for-finding-and-preventing-vulnerabilities-17078.md>)

Original publisher: [Read original article](<https://blog.ethereum.org/en/2023/11/02/writing-robust-c>)

Author: Justin Traglia

Published: 2023-11-02T00:00:00Z

Content type: article

Language: en

Sources: [Ethereum Foundation Blog](<https://devfeed.tech/sources/ethereum-foundation-blog.md>)

Topics: [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [C](<https://devfeed.tech/topics/c.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Library](<https://devfeed.tech/topics/library.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Security](<https://devfeed.tech/topics/security.md>), [LLVM](<https://devfeed.tech/topics/llvm.md>), [make](<https://devfeed.tech/topics/make.md>)

Tags: [c](<https://devfeed.tech/tags/c.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [library](<https://devfeed.tech/tags/library.md>), [llvm](<https://devfeed.tech/tags/llvm.md>), [make](<https://devfeed.tech/tags/make.md>), [research-development](<https://devfeed.tech/tags/research-development.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article explains how Ethereum developers secured the c-kzg-4844 C library used by clients to compute and verify KZG commitments for EIP-4844. It covers LibFuzzer-based testing, differential fuzzing against go-kzg-4844, and coverage analysis with LLVM tools.

### Source excerpt

For EIP-4844, Ethereum clients need the ability to compute and verify KZG commitments. Rather than each client rolling their own crypto, researchers and developers came together to write c-kzg-4844, a relatively small C library with bindings for higher-level languages. The idea was to create a robust and efficient cryptographic library...

## What the fuzz? Better coding through randomized testing

DevFeed: [What the fuzz? Better coding through randomized testing](<https://devfeed.tech/articles/what-the-fuzz-better-coding-through-randomized-testing-13320.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/what-the-fuzz-better-coding-through-randomized-testing>)

Published: 2023-03-13T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Testing](<https://devfeed.tech/topics/testing.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Test-driven development](<https://devfeed.tech/topics/tdd.md>), [Software Engineering](<https://devfeed.tech/topics/software-engineering.md>)

Tags: [code-testing](<https://devfeed.tech/tags/code-testing.md>), [debug](<https://devfeed.tech/tags/debug.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [python](<https://devfeed.tech/tags/python.md>), [research](<https://devfeed.tech/tags/research.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [software-testing](<https://devfeed.tech/tags/software-testing.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [test](<https://devfeed.tech/tags/test.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

This Chainguard article explains how randomized testing and fuzzing can help developers find complicated software bugs. It presents randomized testing as complementary to test-driven development and discusses choosing testing techniques for the right applications.

### Source excerpt

Why do we test our code? Find out in this Chainguard post on the benefits of randomized testing and fuzzing practices.

## High-Throughput, Formal-Methods-Assisted Fuzzing for LLVM

DevFeed: [High-Throughput, Formal-Methods-Assisted Fuzzing for LLVM](<https://devfeed.tech/articles/high-throughput-formal-methods-assisted-fuzzing-for-llvm-39747.md>)

Original publisher: [Read original article](<https://blog.regehr.org/archives/2148>)

Author: regehr

Published: 2022-05-31T14:56:41Z

Content type: article

Language: en

Sources: [Embedded in Academia](<https://devfeed.tech/sources/embedded-in-academia.md>)

Topics: [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [LLVM](<https://devfeed.tech/topics/llvm.md>), [Formal methods](<https://devfeed.tech/topics/formal-methods.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [bug](<https://devfeed.tech/topics/bug.md>)

Tags: [bug](<https://devfeed.tech/tags/bug.md>), [formal-methods](<https://devfeed.tech/tags/formal-methods.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [llvm](<https://devfeed.tech/tags/llvm.md>), [mutation](<https://devfeed.tech/tags/mutation.md>), [testing](<https://devfeed.tech/tags/testing.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>)

### AI overview

The article describes mutation-based fuzzing for LLVM optimization passes, combining a custom LLVM IR mutator with the formal methods tool Alive2 to check whether optimizations are correct or buggy. The authors report that generic mutation with radamsa produced mostly invalid or semantically unchanged tests and found no bugs after several days, motivating a structure-aware mutator that preserves LLVM IR invariants.

### Source excerpt

[This piece is coauthored by Yuyou Fan and John Regehr] Mutation-based fuzzing is based on the idea that new, bug-triggering inputs can often be created by randomly modifying existing, non-bug-triggering inputs. For example, if we wanted to find bugs in a PDF reader, we could grab a bunch of PDF files off the web, mutate [...]

## Kiln Testnet Merge Transition Reveals Client Bugs as Ethereum Testing Continues

DevFeed: [Kiln Testnet Merge Transition Reveals Client Bugs as Ethereum Testing Continues](<https://devfeed.tech/articles/finalized-no-34-17009.md>)

Original publisher: [Read original article](<https://blog.ethereum.org/en/2022/03/23/finalized-no-34>)

Author: Danny Ryan

Published: 2022-03-23T00:00:00Z

Content type: article

Language: en

Sources: [Ethereum Foundation Blog](<https://devfeed.tech/sources/ethereum-foundation-blog.md>)

Topics: [Blockchain](<https://devfeed.tech/topics/blockchain.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Security](<https://devfeed.tech/topics/security.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Network](<https://devfeed.tech/topics/network.md>)

Tags: [blockchain](<https://devfeed.tech/tags/blockchain.md>), [encoding](<https://devfeed.tech/tags/encoding.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [network](<https://devfeed.tech/tags/network.md>), [research-development](<https://devfeed.tech/tags/research-development.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

The article reports that Ethereum's Kiln testnet completed its transition from proof of work to proof of stake. It describes encoding and synchronization errors during the transition and outlines expanded testing, fuzzing, code review, and security efforts ahead of public testnet upgrades.

### Source excerpt

tl;dr Kiln🧱🔥 is up, check it out #TestingTheMerge is in full swing. Do your part, get involved!...

[Next page](<https://devfeed.tech/topics/fuzzing.md?cursor=WyIyMDIyLTAzLTIzVDAwOjAwOjAwKzAwOjAwIiwgIjQyOGI4NDQ5LTcwYjAtNGU1NC04NWI2LWNlMTk1MGVlNjFhNSJd>)