Sign in

Adrian Herrera

@adrianherrera.bsky.social
549 followers 384 following 85 posts

Security researcher with an interest in formal methods. B̶u̶i̶l̶d̶i̶n̶g̶ breaking things @ Interrupt Labs | Teaching @ Australian National University adrian-herrera.com

PostsRepliesMedia
Reposted by Adrian Herrera
Interrupt Labs @interruptlabs.bsky.social · 16/10/2025
Check out the latest from our Labs! Gilbert, in our Browsers team, talks us through how he used one-click memory corruption to exploit a patch-gap in the UC Browser. www.interruptlabs.co.uk/articles/one...
022
Adrian Herrera @adrianherrera.bsky.social · 09/10/2025
Excited to be here with the Interrupt crew!
000
Reposted by Adrian Herrera
ACM SURE Workshop @sureworkshop.bsky.social · 17/09/2025
SURE is proud to announce that we have **9** epic works that have been accepted for presentation at SURE on October 13. Topics span decompilation, (de)obfuscation, debugging, fundamental benchmarks, and more! sure-workshop.org/pa... (paper links out soon)
sure-workshop.org
Accepted Papers | SURE 2025
Papers and posters accepted for SURE 2025
011
Reposted by Adrian Herrera
blacktop.bsky.social @blacktop.bsky.social · 23/08/2025
Created Go bindings for Apple's Hypervisor.framework. Why? Because I wanted to test a Pure Go emulator I'm writing against and couldn't get unicorn2 to work on macOS 26. Plus what's going to be faster than Apple's OWN hypervisor 😎 Check it out! 🎉 github.com/blacktop/go-...
github.com
GitHub - blacktop/go-hypervisor: Apple Hypervisor.framework bindings for Golang
Apple Hypervisor.framework bindings for Golang. Contribute to blacktop/go-hypervisor development by creating an account on GitHub.
064
Reposted by Adrian Herrera
Binary Ninja @binary.ninja · 14/08/2025
Check out our latest blog post on modeling complex control flow with function-level basic block analysis in Binary Ninja 5.1. From DSPs to Brain***k, this update makes it easier to develop plugins for tricky architectures. binary.ninja/2025/08/12/f...
073
Reposted by Adrian Herrera
Johannes Kinder @jkinder.bsky.social · 11/08/2025
🛬 I'm at USENIX Security in Seattle this week, where on Friday at 2pm my former postdoc Tristan Benoit will be presenting our paper "BLens: Contrastive Captioning of Binary Functions using Ensemble Embedding," joint work with Yunru Wang and Moritz Dannehl from my group. Here's the gist:
131
Reposted by Adrian Herrera
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 11/08/2025
WOOT 2025 schedule, all papers are now online open access: usenix.org/conference/w... Talks are recorded, and should be online in a few weeks.
usenix.org
WOOT '25 Technical Sessions
All sessions will be held in Room 611-612 unless otherwise noted.
0128
Reposted by Adrian Herrera
InfoSect @infosectcbr.bsky.social · 01/08/2025
New blog post: Exploiting the Synology TC500 at Pwn2Own Ireland 2024 We built a format string exploit for the TC500 smart cam. It didn’t get used, but it made for a fun case study. blog.infosectcbr.com.au/2025/08/01/e...
blog.infosectcbr.com.au
Exploiting the Synology TC500 at Pwn2Own Ireland 2024
Introduction In October 2024, InfoSect participated in Pwn2Own – a bug bounty competition against embedded devices such as cameras, NAS’, and smart speakers. In this blog, I’ll di…
062
Reposted by Adrian Herrera
Samuel Groß @saelo.bsky.social · 01/08/2025
We released our Fuzzilli-based V8 Sandbox fuzzer: github.com/googleprojec... It explores the heap to find interesting objects and corrupts them in a deterministic way using V8's memory corruption API. Happy fuzzing!
github.com
Add V8SandboxFuzzer · googleprojectzero/fuzzilli@675eccd
This is a basic fuzzer for the V8 Sandbox. It uses the memory corruption API to implement a random-but-deterministic (given a seed) traversal through the V8 heap object graph and corrupts some obje...
0257
Reposted by Adrian Herrera
Linux Kernel Security @linkersec.bsky.social · 15/07/2025
Linux Kernel Hardening: Ten Years Deep Talk by Kees Cook about the relevance of various Linux kernel vulnerability classes and the mitigations that address them. Video: www.youtube.com/watch?v=c_Nx... Slides: static.sched.com/hosted_files...
073
Reposted by Adrian Herrera
raptor @raptor.infosec.exchange.ap.brid.gy · 10/07/2025
CVE-2023-52927: Turning a Forgotten #Syzkaller Report into #kCTF #Exploit qriousec.github.io/post/cve-2023-52…
qriousec.github.io
CVE-2023-52927: Turning a Forgotten Syzkaller Report into kCTF Exploit
Table of Contents I. Introduction II. Netfilter hooks, nf_tables, nf_conntrack, nf_nat and nf_queue 2.1 Netfilter hooks 2.2 nf_tables 2.3 nf_conntrack 2.4 nf_nat 2.5 nf_queue III. The Forgotten Syzkaller Report IV. Root Cause Analysis of a “no reproducer” Syzkaller UAF Report 4.1 Allocation Backtrace 4.2 Free Backtrace 4.3 UAF Backtrace 4.4 Root Cause V. Crafting a Reproducer to Trigger the KASAN UAF 5.1 Allocate a template nf_conn by calling nft_ct_set_zone_eval() 5.2 Setup nf_nat_setup_info() function 5.
062
Adrian Herrera @adrianherrera.bsky.social · 09/07/2025
CTADL - a Datalog-based interprocedural static taint analysis engine for Java/Android bytecode (via JADX) and Pcode (via Ghidra) Code: github.com/sandialabs/c... Talk (via @krismicinski.bsky.social): youtu.be/3ec9VfMUVa8?...
github.com
GitHub - sandialabs/ctadl: CTADL is a static taint analysis tool
CTADL is a static taint analysis tool. Contribute to sandialabs/ctadl development by creating an account on GitHub.
1122
Reposted by Adrian Herrera
Max 'Libra' Kersten @maxkersten.nl · 01/07/2025
Ghidra, scripting, LLM, automagic automation. That should grab the attention for this thread. If you want to read the complete blog, you can do so here: www.trellix.com/blogs/resear... 1/n
A side by side comparison of the original output by Ghidra, and the LLM enriched output.
195
Reposted by Adrian Herrera
Marcel Böhme @mboehme.bsky.social · 02/07/2025
Can we statistically estimate how likely an LLM-generated program is correct w/o knowing what is a correct program for that task? Sounds impossible-but it's actually really simple. In fact, our measure of "correctness" called incoherence can be estimated (PAC guarantees). arxiv.org/abs/2507.00057
arxiv.org
Estimating Correctness Without Oracles in LLM-Based Code Generation
Generating code from natural language specifications is one of the most successful applications of Large Language Models (LLMs). Yet, they hallucinate: LLMs produce outputs that may be grammatically c...
1123
Reposted by Adrian Herrera
dmnk @dmnk.bsky.social · 17/06/2025
Firmwire 🤝 LibAFL
081
Reposted by Adrian Herrera
raptor @raptor.infosec.exchange.ap.brid.gy · 14/06/2025
Solo: A Pixel 6 Pro Story (When one #bug is all you need) starlabs.sg/blog/2025/06-solo-a-pix…
starlabs.sg
Solo: A Pixel 6 Pro Story (When one bug is all you need)
During my internship I was tasked to analyze a Mali GPU exploit on Pixel 7/8 devices and adapt it to make it work on another device: the Pixel 6 Pro. While the exploit process itself is relatively straightforward to reproduce (in theory we just need to find the correct symbol offsets and signatures for our target device), what’s interesting about Pixel 6 Pro is that it uses a different Mali GPU from the Pixel 7/8, which lacked support for a feature that one of the two vulnerabilities within the exploit relied on:
011
Reposted by Adrian Herrera
Rohan Padhye @rohan.padhye.org · 06/06/2025
Just Accepted to ACM TOSEM! The "Havoc Paradox" is about the relationship between byte-level fuzzer mutations and their effect on the inputs produced by generators for structured strings (e.g. XML/SQL). Can disruptive mutations be controlled? Should they be? Find out. 📄 dl.acm.org/doi/pdf/10.1...
2203
Reposted by Adrian Herrera
Romain Thomas (@rh0main) @rh0main.bsky.social · 27/05/2025
[Blog Post] New high-level API in LIEF that allows the creation of DWARF files. Additionally, I present two plugins designed to export program information from Ghidra and BinaryNinja into a DWARF file. lief.re/blog/2025-05... (Bonus: DWARF file detailing my reverse engineering work on DroidGuard)
lief.re
DWARF as a Shared Reverse Engineering Format
This blog post introduces a new API in LIEF to create DWARF files
12215
Reposted by Adrian Herrera
GitHub Security Lab @securitylab.github.com · 23/05/2025
Our team member Man Yue Mo is back, showing a new way to bypass MTE protection on Android phones with CVE-2025-0072. github.blog/security/vul...
github.blog
Bypassing MTE with CVE-2025-0072
See how a vulnerability in the Arm Mali GPU can be exploited to gain kernel code execution even when Memory Tagging Extension (MTE) is enabled.
063
Reposted by Adrian Herrera
Zao Yang @zaoyang.bsky.social · 22/05/2025
Happy to share my upcoming #ATC25 paper w/ @snagycs.bsky.social: "BIN2WRONG: a Unified Fuzzing Framework for Uncovering Semantic Errors in Binary-to-C Decompilers"! Bin2Wrong creates binaries by mutating source, compiler, optimizations, and format—revealing 48 new bugs in 7 decompilers! 💪
142
Reposted by Adrian Herrera
Sam Thomas @xorpse.ghost.sh · 21/05/2025
We're are happy to announce a new release of our #Rust bindings for idalib. What's new: - New APIs for working with IDBs, segments, and more - Rust 2024 support - New homepage: idalib.rs H/T to our contributors @yeggor.bsky.social & @raptor.infosec.exchange.ap.brid.gy github.com/binarly-io/i...
github.com
GitHub - binarly-io/idalib: Idiomatic Rust bindings for the IDA SDK, enabling the development of standalone analysis tools using IDA v9.x’s idalib
Idiomatic Rust bindings for the IDA SDK, enabling the development of standalone analysis tools using IDA v9.x’s idalib - binarly-io/idalib
059
Reposted by Adrian Herrera
sam4k @sam4k.com · 08/05/2025
with offensivecon around the corner, i figured id write another post on linux kernel exploitation techniques - this time i cover the world of page table exploitation! enjoy 🤓 sam4k.com/page-table-k...
sam4k.com
Kernel Exploitation Techniques: Turning The (Page) Tables
This post explores attacking page tables as a Linux kernel exploitation technique for gaining powerful read/write primitives.
1134
Reposted by Adrian Herrera
Andrey Konovalov @andreyknvl.bsky.social · 06/05/2025
Gave a talk on external fuzzing of Linux kernel USB drivers with syzkaller at SAFACon. Includes a demonstration of how to rediscover CVE-2024-53104, an out-of-bounds bug in the USB Video Class driver. Slides: docs.google.com/presentation...
122
Reposted by Adrian Herrera
blacktop.bsky.social @blacktop.bsky.social · 05/05/2025
Wrote a lil' guide to help get people started with the 🆕 `ipsw` AI decompiler 📖 blacktop.github.io/ipsw/docs/gu...
blacktop.github.io
Decompiler | ipsw
Using the AI decompiler.
021
Adrian Herrera @adrianherrera.bsky.social · 01/05/2025
Can confirm the hardware lab is pretty cool 😎
051
Reposted by Adrian Herrera
Andreas Zeller @andreaszeller.bsky.social · 28/04/2025
In today's #AST2025 keynote on our new #Fandango fuzzer, I presented ongoing extensions for protocol fuzzing, oracle checking, coverage guidance, much more. Slides now available: conf.researchr.org/details/ast-...
conf.researchr.org
Personalized Fuzzing (AST 2025) - AST 2025
The 6th ACM/IEEE International Conference on Automation of Software Test (AST 2025) Software pervasiveness in both industry and digital society, as well as the proliferation of Artificial Intelligenc...
1133
Reposted by Adrian Herrera
Romain Thomas (@rh0main) @rh0main.bsky.social · 28/04/2025
Fuzzing Windows ARM64 binaries with a DBI and LLVM? Here we go: www.romainthomas.fr/post/25-04-w...
045
Reposted by Adrian Herrera
Zion Leonahenahe Basque @mahal0z.bsky.social · 25/04/2025
I'm proud to announce that myself and @AtipriyaBajaj have created the Workshop on Software Understanding and Reverse Engineering (SURE), which will be co-located at CCS 2025. sure-workshop.org/ Please follow our workshop account @sureworkshop and RT it for visibility :).
sure-workshop.org
SURE 2025 | The Workshop on Software Understanding and Reverse Engineering
The Workshop on Software Understanding and Reverse Engineering
176
Reposted by Adrian Herrera
dmnk @dmnk.bsky.social · 25/04/2025
Just skimmed over or it so far but looks like a nice overview on snapshot fuzzing by @theoabel.com fuzzinglabs.com/state-of-lin...
fuzzinglabs.com
Linux Hardening - State Of Linux Snapshot Fuzzing​
Explore the current state of Linux snapshot fuzzing, its challenges, tools, and impact on kernel security.
073
Reposted by Adrian Herrera
lukas seidel @pr0me.bsky.social · 23/04/2025
the guy who reversed the denuvo drm @momo5502.bsky.social works on a high-perf windows emulator for security research. I noticed that it supports icicle as a backend, a fuzzing-specific emulator. awesome to see academic work being continuously developed and making it into the real world
263
Reposted by Adrian Herrera
epsilon-sec.com @epsilon-sec.com · 20/04/2025
About to celebrate Easter with your family but don't know what to talk about at the table? Then don't lose time and read our new article about RPAC! Written by @zadig.trollab.org ! blog.epsilon-sec.com/cve-2025-312...
happy easter
034
Adrian Herrera @adrianherrera.bsky.social · 21/04/2025
“15,000 lines of verified cryptography now in Python” Nice write up on integrating the hash and HMAC routines from the HACL* verified crypto library into Python 🎉 jonathan.protzenko.fr/2025/04/18/p...
jonathan.protzenko.fr
15,000 lines of verified cryptography now in Python
In November 2022, I opened issue 99108 on Python’s GitHub repository, arguing that after a recent CVE in its implementation of SHA3, Python should embrace verified code for all of its hash-related inf...
000
Reposted by Adrian Herrera
Meysam @r00tkitsmm.bsky.social · 10/04/2025
My new blog post, which I presented at #Zer0Con2025 A binary level macOS KEXT kernel address sanitizer r00tkitsmm.github.io/fuzzing/2025...
r00tkitsmm.github.io
Pishi Reloaded: Binary only address sanitizer for macOS KEXT.
In the part 1 of my tutorial style blog post about fuzzing, I discussed how we can instrument the macOS KEXTs to collect code coverage at the basic block or edge level.
0134
Reposted by Adrian Herrera
Andreas Zeller @andreaszeller.bsky.social · 10/04/2025
What do you get if you combine #grammars, #constraints, #evolutionary algorithms, and #Python in one? A mighty fuzzer! Check out our latest #FANDANGO work, to appear at #ISSTA2025: publications.cispa.de/articles/sta... To try out Fandango yourself, check out its home page: fandango-fuzzer.github.io
FANDANGO: Evolving Language-Based Testing
José Antonio Zamudio Amaya, Marius Smytzek, Andreas Zeller

Language-based fuzzers leverage formal input specifications (languages) to generate arbitrarily large and diverse sets of valid inputs for a program under test. Modern language-based test generators combine grammars and constraints to satisfy syntactic and semantic input constraints. ISLa, the leading input generator in that space, uses symbolic constraint solving to solve input constraints. Using solvers places ISLa among the most precise fuzzers but also makes it slow.

In this paper, we explore search-based testing as an alternative to symbolic constraint solving. We employ a genetic algorithm that iteratively generates candidate inputs from an input specification, evaluates them against defined constraints, evolving a population of inputs through syntactically valid mutations and retaining those with superior fitness until the semantic input constraints are met. This evolutionary procedure, analogous to natural genetic evolution, leads to progressively improved inputs that cover both semantics and syntax. This change boosts the efficiency of language-based testing: In our experiments, compared to ISLa, our search-based FANDANGO prototype is faster by one to three orders of magnitude without sacrificing precision.

The search-based approach no longer restricts constraints to constraint solvers' (miniature) languages. In FANDANGO, constraints can use the whole Python language and library. This expressiveness gives testers unprecedented flexibility in shaping test inputs. It allows them to state arbitrary goals for test generation: "Please produce 1,000 valid test inputs where the <voltage> field follows a Gaussian distribution but never exceeds 20 mV."
0244
Reposted by Adrian Herrera
Synacktiv @synacktiv.com · 09/04/2025
From firmware dumps to wireless exploration — check out our latest dive into DVB receiver analysis and the hidden attack surface it exposes! www.synacktiv.com/en/publicati...
synacktiv.com
Hack the channel: A Deep Dive into DVB Receiver Security
Introduction During a garage cleaning, we found a DVB receiver and thought it would be a great target for vulnerability research.
01211
Reposted by Adrian Herrera
buherator @buherator.bsky.social · 08/04/2025
Fun fact: you can attach to the gdbserver exposed by #rr and do #TimeTravelDebugging from #Ghidra :) UX is similar to ret-sync. Original->
Alt text TBD, sorry!
085
Adrian Herrera @adrianherrera.bsky.social · 29/03/2025
Saturday morning read: “QUIC-Fuzz: An Effective Greybox Fuzzer For The QUIC Protocol” arxiv.org/abs/2503.19402
An iPad with the QUIC-Fuzz paper
0123
Reposted by Adrian Herrera
afd-icl.bsky.social @afd-icl.bsky.social · 26/03/2025
Check out or work on automated testing of MLIR compilers, which Jacob Yu will present at @ASPLOSConf next week (joint work with Nick Wu) www.doc.ic.ac.uk/~afd/papers/...
0133
Reposted by Adrian Herrera
Caroline Lemieux @cestlemieux.bsky.social · 21/03/2025
There's still time to submit to FUZZING'25! This year, we're accepting both the (now classic) registered reports _and_ new short papers (fuzzing nuggets). Deadline is now March 26th! fuzzingworkshop.github.io
fuzzingworkshop.github.io
FUZZING'25 Workshop @ ISSTA
The 4th International Fuzzing Workshop (FUZZING) 2025 welcomes all researchers, scientists, engineers and practitioners to present their latest research findings, empirical analyses, t...
296
Adrian Herrera @adrianherrera.bsky.social · 20/03/2025
Looks fun! Under-constrained symbolic execution for ARM, PPC, and x86 binaries + LLM bitcode. Also plugs into Ghidra.
091
Reposted by Adrian Herrera
Gabriel Sherman @gabriel-sherman.bsky.social · 17/03/2025
Need a fuzzing harness? No time to write one? Tired of false-positives? Let OGHarn lead the way to bug discovery!🐞 I'm excited to share my paper(with @snagycs.bsky.social)"No Harness, No Problem: Oracle-guided Harnessing for Auto-generating C API Fuzzing Harnesses" at @icseconf.bsky.social 2025!
1176
Reposted by Adrian Herrera
lukas seidel @pr0me.bsky.social · 12/03/2025
libAFL is a beast. it has so many settings to tweak, different modes to select and the code can be quite scary at first. but writing a target-specific custom fuzzer is super powerful! to get started, Trail of Bits just published a nice primer: appsec.guide/docs/fuzzing...
appsec.guide
LibAFL
LibAFL # The LibAFL fuzzer implements features from AFL-based fuzzers like AFL++. Similarly to AFL++, LibAFL provides better fuzzing performance and more advanced features over libFuzzer. However, wit...
071
Reposted by Adrian Herrera
Alex Bradbury @asbradbury.org · 11/03/2025
My total rewrite of the instructions on cross-compiling Clang/LLVM for Linux using Clang/LLVM for Linux has now landed. If you want to cross-compile LLVM without getting angry - this is your guide! llvm.org/docs/HowToCr...
llvm.org
How to cross-compile Clang/LLVM using Clang/LLVM — LLVM 21.0.0git documentation
0199
Reposted by Adrian Herrera
nSinus-R @nsinusr.bsky.social · 05/03/2025
Really enjoyed speaking at the inaugural edition of @re-verse.io! You can find Tomasz' and my slides on tricks with SIMs and interposers here: tinyurl.com/reverse25-si...
Roadmap of the SIMsalabim re-verse.io talk. It shows the backplane of a disassembled Pixel 6 phone together with a iconized SIM and a picture of an interposer. Five locations are marked: (0) SIM interface, (1) Baseband, (2) Attack Surface, (3) Vulnerabilities, (4) Interposer
0247
Reposted by Adrian Herrera
lukas seidel @pr0me.bsky.social · 03/03/2025
I had a blast speaking and being at the RE//verse conference! so many cool people and great discussions on firmware, fuzzing, ai and binary analysis if you want to find out more about firmware rehosting or are an enjoyer of ascii diagrams, check out the slides to my talk below :)
183
Reposted by Adrian Herrera
Zion Leonahenahe Basque @mahal0z.bsky.social · 01/03/2025
If you are looking for my slides from my Reverse talk, you can find it and useful artifacts here: github.com/mahaloz/t...
github.com
talks/2025/REverse_SAILR at main · mahaloz/talks
A repo for holding talk artifacts, including a summary, slides, and demo PoCs - mahaloz/talks
076
Reposted by Adrian Herrera
Usenix WOOT Conference on Offensive Technologies @wootsecurity.bsky.social · 28/02/2025
Only a week and a half left for USENIX WOOT '25 conference submissions - deadline March 11 AoE. We’re looking forward to seeing even more of your amazing offensive security papers this year! And still a few days for up-and-coming track (March 4). CfP at www.usenix.org/conference/w...
0510
Reposted by Adrian Herrera
Sam Thomas @xorpse.ghost.sh · 28/02/2025
We @binarly.bsky.social are pleased to announce a new release of our Rust bindings for Hex-Rays IDA Pro (crates.io/crates/idalib) with support for the latest v9.1 release! Special thanks to @yeggor.bsky.social for taking care of the changes needed to make everything compatible with this release!
crates.io
crates.io: Rust Package Registry
072
Reposted by Adrian Herrera
gannimo.bsky.social @gannimo.bsky.social · 27/02/2025
Interested in #fuzzing #hypervisors? With Truman we create precise device models that are state-aware and precisely mutate message sequences #NDSS25 nebelwelt.net/blog/2025/02...
nebelwelt.net
Truman: discovering hypervisor bugs through virtual device models
Hypervisors power not just the cloud but are becoming a commodity in mobile phones and desktops as well. They separate virtual machines from each...
021
Reposted by Adrian Herrera
gannimo.bsky.social @gannimo.bsky.social · 27/02/2025
Did you always want to fuzz with #MSan but were worried about false positives? Fear no more, with QMsan #NDSS25, we create a binary-rewriting based approach that reduces false positives efficiently! nebelwelt.net/blog/2025/02...
nebelwelt.net
QMSan: discovering uninitialized memory errors in binaries
Sanitizers serve as the primary bug detection Oracle during automated testing. They
051