Our solution? An AI dual-agent pipeline (Protocol Expert + Fuzz Writer) with self-correcting feedback loops. It automatically bypasses coverage plateaus, generating stable fuzz targets in hours instead of weeks. Come see how we're scaling this to 200+ devices!
Excited to present at Open Source Summit 2026! 🚀 I'll be sharing how our team is automating vulnerability discovery in my talk: "Hardening QEMU with Self-Correcting Fuzzing Pipelines."
🔗 [https://t.co/PxL3uuZDft](https://t.co/L26dswR6hz)
#OSSummit#QEMU#Fuzzing
Fuzzing a hypervisor like QEMU is notoriously hard. Traditional fuzzers fail at stateful protocols, feeding devices gibberish. To find deep bugs, we can't limit ourselves to PIO or MMIO; any potential callback to a device-specific function can be an entry point.
🚀 2026 PhD Internship at @Google
I’m hosting a PhD intern in 2026! We’ll be researching
Hypervisor Security and Program Analysis, with a focus on how LLMs can
transform vulnerability detection.
Feel free to reach out!
Hello aspiring hackers! Every summer, we host high school cybersecurity enthusiasts from around the Phoenix valley for summer internships through ASU’s Center for Cybersecurity and Trusted Foundations! Applications for this summer close in under a week! https://t.co/108RGMdLBI
Hello hackers! Finished all the awesome challenges on https://t.co/VBZlmDUtBg? Ready for more? It's your lucky day! Today, we're launching a new https://t.co/yjFhiLYc7V feature: Community Dojos full of new and exciting challenges to tackle and learn from!
Read on! 🧵
Check out the recent blog post from @openssf on Fuzz Introspector developments and what's new! Macro-level insights on open source fuzzing, search for #fuzzing details in more than one million functions, automatic fuzz harness generation and more!
Happy to share our FUZZING'23 paper on analyzing fuzz blockers: https://t.co/CzQR5iIFzW. This work is led by my PhD student @WentaoGao5 in collaboration w/ @Alan32Liu, @halbecaf, @tobycmurray, and @bipr. Can't wait to e-meet #fuzzing lovers in the workshop next week @issta_conf!!
This is exactly what developing should look like. It's insane how big the difference between "what's possible" and "what we actually do" is. If you are interested in dev tooling at all, please spend the few minutes watching this.
I've been reflecting on recent events & how different my life would've been if my parents returned to Iran.
I stand with the courageous women & allies protesting for freedom. My heavy heart goes out to the family & friends of #MahsaAmini & others that were senselessly murdered.
We published a blogpost on SystemSan - our sanitizer for command injection which found a remote code execution vulnerability in tinygltf.
https://t.co/7NQr4wSPvA
We will pay rewards for sanitizers that can find non C/C++ specific vulnerabilities such as SQLI, XSS, and SSRF.
Proof that fuzzing can discover exploitable vulnerabilities that aren't memory corruption! OSS-Fuzz discovered a very interesting command injection vulnerability which was just fixed: https://t.co/QOw9Vv26RE