AI-powered fuzzing is changing how we find vulnerabilities. GitHub Security Lab’s new Fuzzing Taskflow uses an LLM agent to automate the end-to-end fuzzing workflow for C/C++ projects—from identifying entry points and writing harnesses to improving coverage, triaging crashes, and generating vulnerability reports. Built on the GitHub Security Lab Taskflow Agent, it helps security researchers and maintainers spend less time babysitting fuzzers and more time investigating meaningful findings. Read Antonio Morales Maldonado's blog post and explore how autonomous fuzzing works: https://lnkd.in/gfGYpkhh #ApplicationSecurity #Fuzzing #AI #OpenSourceSecurity #Cybersecurity #GitHubSecurityLab
AI-Powered Fuzzing for C/C++ Projects on GitHub Security Lab
More Relevant Posts
-
Top 13 GitHub repos to make your startup harder to hack 👇 These tools cover everything from finding vulnerable dependencies and leaked secrets to testing your app and securing the AI coding agents building it. If you’re vibe coding or shipping fast, check them out. They can help you catch vulnerabilities before someone else does: 1/ OSV-Scanner by Google (⭐️ 11.1k, launched in 2021) https://lnkd.in/gshcFw73 Finds known vulnerabilities hiding inside your dependencies. 2/ CodeQL by GitHub (⭐️ 10.1k, launched in 2019) https://lnkd.in/g539KKFW Finds security vulnerabilities and dangerous patterns directly in your source code. 3/ Infer by Meta (⭐️ 15k+, launched in 2016) https://lnkd.in/giAct97G Static analysis for catching bugs and unsafe code before you ship. 4/ ZAP by Checkmarx (⭐️ 15.8k, launched in 2010) https://lnkd.in/gz8GV_GZ Tests your running web app for vulnerabilities an attacker could exploit. 5/ Trivy by Aqua Security (⭐️ 38k, launched in 2019) https://lnkd.in/gAtwXxm5 Finds vulnerabilities, misconfigurations and exposed secrets across your stack. 6/ Kingfisher by MongoDB (⭐️ 1.2k, launched in 2025) https://lnkd.in/g6NP4Xf2 Finds leaked credentials, checks if they’re still live, and shows what they could expose. 7/ OpenClarity (⭐️ 1.5k, launched in 2022) https://lnkd.in/gerwdXFX Finds vulnerabilities, malware, leaked secrets and supply-chain risks across cloud environments. 8/ Harden AIF (⭐️ 1k+, launched in 2026) https://lnkd.in/g5SuyjYv On-device security for coding agents that stops dangerous actions before they execute. 9/ GUAC by OpenSSF (⭐️ 1.5k, launched in 2022) https://lnkd.in/gc7AJa7P Maps your software supply chain to surface dependencies, vulnerabilities and security risks. 10/ TruffleHog by Truffle Security Co. (⭐️ 28.1k, launched in 2020) https://lnkd.in/gHPBMDaC Finds and verifies exposed API keys, passwords and other credentials across your stack. 11/ Gitleaks (⭐️ 29.5k, launched in 2018) https://lnkd.in/gtBFKz9c Finds secrets accidentally committed to your Git repos. 12/ Nuclei by ProjectDiscovery (⭐️ 31.5k, launched in 2021) https://lnkd.in/gUEG2ZBm Scans your apps, APIs and infrastructure for known vulnerabilities. 13/ Nuclei Templates by ProjectDiscovery (⭐️ 13k, launched in 2021) https://lnkd.in/gfjbyjwG Thousands of community-maintained checks for known vulnerabilities and exposures. AI made shipping software ridiculously fast. Probably worth making sure it didn’t ship the vulnerability too. 📌 Save this list and share with other builders and founders in your network!
To view or add a comment, sign in
-
-
An autonomous AI agent found admin access to a well-funded AI infrastructure startup's entire GitHub org in 25 minutes. I spent the weekend testing the tool that did it. The agent is Strix, open-source and free to run yourself. A security team pointed it at Baseten's public infrastructure and it found a GitHub personal access token sitting in the build history of a public Docker image — baked in as a build argument back in March 2023, never rotated since. That token had admin and push access to Baseten's main product repo, the GitOps repo driving their infrastructure, and their Homebrew tap. Baseten patched it by the next afternoon. That's what got me curious enough to run it myself rather than just read about it. Wanted to see what an agent like this actually does day to day, not just the headline case. Only covered a handful of use cases so far, nothing exhaustive, but a few things stood out: - Multi-target testing — same tool works against source code and a deployed app, not just one or the other - Hooks into GitHub Actions, so it runs as part of your PR pipeline instead of a one-off scan - Focused security review of a specific GitHub repo, just by pointing it at the URL - Black-box web application assessment against a live domain, no source access needed None of this is revolutionary in isolation — pentesters and scanners already do all of it. What's different is one agent moving across all of them without switching tools or writing new scripts for each mode. Still early days on my end — planning to build out a proper sandbox and push it harder. Will post an update once I've gone deeper with real findings. 🫡 IMHO: tools like this are quietly becoming the default first pass in a security workflow, not a novelty. Worth having on your radar even if you're not ready to hand it the keys yet. 🚀 Repo: https://lnkd.in/gTgPCkT4 The Baseten find, for context: https://lnkd.in/g_FhKhwV #AIAgents #CyberSecurity #AppSec #AgenticAI #DevSecOps
To view or add a comment, sign in
-
An application built on the official MCP Python SDK could be tricked into giving away its OAuth credentials to a malicious server, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and 2.2.0. #cyber #cybersecurity #hacking #ciso #informationsecurity #applicationsecurity https://lnkd.in/dJ_DNUmC
To view or add a comment, sign in
-
Mandiant has disclosed an incident in which an attacker hijacked an active AI coding assistant session at a software-as-a-service provider and used a compromised PyPI package to steal repository secrets, source code and GitHub OAuth tokens before spreading the Shai-Hulud worm across approximately 100 internal code repositories. Read More: https://lnkd.in/dRhYdk28 CXO Media #Mandiant #Cybersecurity #AI #ArtificialIntelligence #AICoding #AIAgents #SoftwareSecurity #ApplicationSecurity #SupplyChainSecurity #CyberThreats #Malware #ShaiHulud #PyPI #GitHub #CloudSecurity
To view or add a comment, sign in
-
Private GitHub Is a Loud Command Channel Private GitHub is live C2, and the AI-escape story is cover. See what this week's cybersecurity failures mean for your repos. #APT #AWS #threatintel #cybersecurity #infosec #IPBan Read the full article at https://lnkd.in/d3xDfY74
To view or add a comment, sign in
-
CVE-2026-53576 Lets Anyone Run Arbitrary Root Commands on Kestra Hosts A public PoC is now live on GitHub, letting unauthenticated users spin up root-level Docker containers through Kestra’s REST API. #cyrbmonk #cybersecurity #threatintelligence #infosec #informationsecurity #cyber
To view or add a comment, sign in
-
CVE-2026-32604 Lets Attackers Run Commands Inside Spinnaker Clouddriver Pods, Exploit Code Is Live on GitHub A critical remote code execution flaw in pre-2026.1.0 Spinnaker is now exploitable with publicly available proof-of-concept code. #cyrbmonk #cybersecurity #threatintelligence #infosec #informationsecurity #cyber
To view or add a comment, sign in
-
As AI accelerates software delivery, security can no longer operate at yesterday's speed. The organizations that win will not be those that find the most vulnerabilities. They will be those that shorten the time between risk identification and remediation. That's the idea behind my latest article on security feedback loops and what modern platforms (or even older ones using COBOL) can teach us about scaling security without slowing the business down. I wanted to share my thoughts after a great session from GitHub with Leonardo Quimbaya and Eric Tooley from GitHub. Read more: https://lnkd.in/dd9Ysg9v #Leadership #CyberSecurity #CISO #BusinessTransformation #AI
To view or add a comment, sign in
-
A fresh proof-of-concept on GitHub lets anyone pull arbitrary files from any GitLab server, and the bug scores a perfect 10.0. #cyrbmonk #cybersecurity #threatintelligence #infosec #informationsecurity #cyber
To view or add a comment, sign in
-
🐝 25+ OWASP® Foundation events in September 🐝 Get involved with the OWASP global network this month. Find a local chapter meetup, connect with other practitioners, and dig into application security with one of the best communities in the space. 1️⃣ Chapter meetings worldwide 🌎 2️⃣ Workshops & CTFs 3️⃣ OWASP 25th Anniversary Virtual Conference 4️⃣ Networking & community Hosted by OWASP Santa Barbara, OWASP® Foundation, OWASP LA, OWASP Boston, OWASP Las Vegas, SecureFlag, OWASP Germany, OWASP Toronto Chapter, OWASP Manchester, OWASP Orange County, OWASP Denver, OWASP Riyadh, OWASP Leiria, OWASP New Zealand Chapter, AppSec New Zealand, OWASP Dorset, Cyber Peterborough, and many others. Explore all upcoming OWASP events: ➡️ https://lnkd.in/g96DJDsk #InfoSec #CyberSecurity #OWASP #Community
Join us next Tuesday for a hands-on Secure Development Workshop & CTF with SecureFlag! 🚩 Participants will identify and fix real-world vulnerabilities in a live coding environment, then join us for dinner and networking with the local security community. Top finishers win cash and other prizes. 📅 Tuesday, September 15 - 5:30 PM 📍 Workzones, Paseo Nuevo, Santa Barbara RSVP (free): https://lnkd.in/gjx2VJ3m #AppSec #InfoSec #CyberSecurity #SantaBarbara
To view or add a comment, sign in