Sign in

Cornelius Aschermann

@is-eqv.bsky.social
388 followers 96 following 35 posts

Fuzzing & stuff hexgolems.com

PostsRepliesMedia
Reposted by Cornelius Aschermann
Gynvael Coldwind @gynvael.bsky.social · 27/07/2026
Issue #9 of the free @pagedout.bsky.social zine is here! 90 pages of pure technical awesomeness! Please help spread the news ❤️ Web: pagedout.institute/webview.php?... PDF: pagedout.institute/download/Pag... Wallpaper: pagedout.institute/download/Pag... Patreon: www.patreon.com/cw/PagedOut Enjoy!
pagedout.institute
Paged Out!
Deeply technical zine. And it's free.
0146
Reposted by Cornelius Aschermann
Richard Johnson @richinseattle.bsky.social · 07/03/2026
Spread the word! @phrack.org CFP with demoscene cracktro is live. Turn up the volume and enjoy the awesome stylings of @PiotrBania with some hopefully inspiring text from phrack staff :) phrack.org
02817
Reposted by Cornelius Aschermann
Yannic Noller @yannicnoller.bsky.social · 08/10/2025
#FUZZING'26 CALL FOR PAPERS ────── ✨ After 5 years, we will be again co-located with NDSS! 🔗 fuzzing-workshop.github.io 📅 11. Dec (Submission) //cc @mboehme.bsky.social (MPI-SP), @ruijiemeng.bsky.social (CISPA), @rohan.padhye.org (CMU), László Szekeres (Google)
0104
Reposted by Cornelius Aschermann
dmnk @dmnk.bsky.social · 26/10/2025
Must-read for fuzzing folks (read: tooling/algorithms/academia) by Addison Crump addisoncrump.info/research/wha...
addisoncrump.info
What the hell are we doing? · Addison Crump
Homepage for Addison Crump
13011
Cornelius Aschermann @is-eqv.bsky.social · 21/09/2025
Thanks to Viet Hoang Luu's effort AFL++ just got IJON support: github.com/AFLplusplus/...
github.com
IJON Full Implementation by vi3tL0u1s · Pull Request #2540 · AFLplusplus/AFLplusplus
IJON Full Implementation This is a complete implementation of all IJON features for source code instrumentation in AFL++. Base commit: 6b6cc9c1 Note to maintainers: This PR is based on a commit, th...
070
Cornelius Aschermann @is-eqv.bsky.social · 21/09/2025
drops.dagstuhl.de/storage/01oa... can we get this builtin in lldb please?
drops.dagstuhl.de
020
Reposted by Cornelius Aschermann
dmnk @dmnk.bsky.social · 15/07/2025
Our Big Sleep LLM Agent found critical vulns 📈📈📈 #BigSleep blog.google/technology/s...
blog.google
A summer of security: empowering cyber defenders with AI
Here’s what we’re announcing at cybersecurity conferences like Black Hat USA and DEF CON 33.
091
Reposted by Cornelius Aschermann
David Buchanan @retr0.id · 31/05/2025
cut my heap into pieces, this is my crash report: allocation, no alignment don't give a fuck if it faults on assignment this is fatal abort()
643975
Reposted by Cornelius Aschermann
Stefan Nagy @snagycs.bsky.social · 28/04/2025
✈️ I'll be at @icseconf.bsky.social this week — find me if you'd like to chat about all things fuzzing / binary analysis!
031
Reposted by Cornelius Aschermann
Zion Leonahenahe Basque @mahal0z.bsky.social · 25/04/2025
I'm proud to announce that myself and @AtipriyaBajaj have created the Workshop on Software Understanding and Reverse Engineering (SURE), which will be co-located at CCS 2025. sure-workshop.org/ Please follow our workshop account @sureworkshop and RT it for visibility :).
sure-workshop.org
SURE 2025 | The Workshop on Software Understanding and Reverse Engineering
The Workshop on Software Understanding and Reverse Engineering
176
Reposted by Cornelius Aschermann
Marcel Böhme @mboehme.bsky.social · 24/04/2025
Our paper "Top Score on the Wrong Exam" paper will be presented at #ISSTA25 🐣 in Trondheim! 📝https://mpi-softsec.github.io/papers/ISSTA25-topscore.pdf 🧑‍💻https://github.com/niklasrisse/TopScoreWrongExam // @nrisse.bsky.social @fuzzing.bsky.social
1205
Reposted by Cornelius Aschermann
Caroline Lemieux @cestlemieux.bsky.social · 21/03/2025
There's still time to submit to FUZZING'25! This year, we're accepting both the (now classic) registered reports _and_ new short papers (fuzzing nuggets). Deadline is now March 26th! fuzzingworkshop.github.io
fuzzingworkshop.github.io
FUZZING'25 Workshop @ ISSTA
The 4th International Fuzzing Workshop (FUZZING) 2025 welcomes all researchers, scientists, engineers and practitioners to present their latest research findings, empirical analyses, t...
296
Cornelius Aschermann @is-eqv.bsky.social · 18/03/2025
futures.cs.utah.edu/papers/25ICS... by @snagycs.bsky.social and @gabriel-sherman.bsky.social Seems like a very sensible approach to harness generation with some impressive results. I'm looking forward to seeing more discussion about this approach :) (sorry for blatantly copying the twitter thing).
0111
Cornelius Aschermann @is-eqv.bsky.social · 04/03/2025
Just earlier today I was talking to someone how we are missing out A LOT of power from dynamic language reflection/introspection capabilities in fuzzing, and then I saw this paper: nebelwelt.net/publications... - great timing & work @gannimo.bsky.social!
nebelwelt.net
151
Reposted by Cornelius Aschermann
dmnk @dmnk.bsky.social · 23/02/2025
Leude geht wählen. Vote whatever Elon didn't endorse
041
Cornelius Aschermann @is-eqv.bsky.social · 06/02/2025
Super cool to see people build ontop of Nyx: neodyme.io/en/blog/hype...
neodyme.io
Introducing HyperHook: A harnessing framework for Nyx
In this post, we introduce HyperHook, a harnessing framework for snapshot-based fuzzing for user-space applications using Nyx. HyperHook simplifies guest-to-host communication and automates repetitive...
042
Reposted by Cornelius Aschermann
Carl Smith @rwx.page · 04/02/2025
I’m very excited to announce that we at V8 Security have finally published our first version of Fuzzilli that understands Wasm! Go check it out at github.com/googleprojectzero/fuzzil…. While we still have a way to go in improving it, we think it shows a promising approach!
13116
Cornelius Aschermann @is-eqv.bsky.social · 04/02/2025
aischolar.0x434b.dev Pretty cool project by @434b.bsky.social: A neat web interface to explore security (and in particular: Fuzzing) papers with AI summaries. Seems super useful to get/stay up to date with recent papers :)
aischolar.0x434b.dev
AIScholar - Paper Database
0106
Reposted by Cornelius Aschermann
ading.dev @ading.dev · 31/01/2025
I got Linux running in a PDF file using a RISC-V emulator. PDFs support Javascript, so Emscripten is used to compile the TinyEMU emulator to asm.js, which runs in the PDF. It boots in about 30 seconds and emulates a riscv32 buildroot system. linux.doompdf.dev/linux.pdf github.com/ading2210/li...
12311129
Cornelius Aschermann @is-eqv.bsky.social · 27/01/2025
I have long argued that fuzzers are better at tracking taint than taint tracking. @andreaszeller.bsky.social et Al. build a info leak fuzzer (w/o taint tracking): dl.acm.org/doi/pdf/10.1.... It finds 10 old CVEs (ASAN: 1). Cool to see a PoC! Would probably work better with snapshot fuzzing tho ;)
Table from the paper that showst that FLOWFUZZ discovers 10 old CVEs, using just ASAN instead of output differentials only discovers 1
0184
Cornelius Aschermann @is-eqv.bsky.social · 31/12/2024
pacibsp.github.io/2024/invaria... Another great blogpost displaying the "The compiler is an evil djinn, secretly trying to corrupt your wishes with the moral compass of tobacco industry lawyers"-model of C semantics.
pacibsp.github.io
“Invariant inversion” in memory-unsafe languages
One way of seeing the difference between memory-safe and memory-unsafe languages is that in a memory-safe language, the invariants used to uphold memory safety only “lean on” invariants that are enfor...
1135
Reposted by Cornelius Aschermann
dmnk @dmnk.bsky.social · 24/12/2024
Re-sharing to keep bluesky rolling go.bsky.app/EhGFSVj
04513
Reposted by Cornelius Aschermann
Marcel Böhme @mboehme.bsky.social · 28/11/2024
🔥 No fuzz drivers needed. Our paper on injecting greybox fuzzers into running systems at user-defined amplifier points (in-vivo fuzzing) was accepted at #ICSE25! 📝 mboehme.github.io/paper/ICSE25... 🧑‍💻 github.com/OctavioGalla... (subject to AE) //Lead by Octavio Galland (former #MPI_SP intern).
14011
Cornelius Aschermann @is-eqv.bsky.social · 28/11/2024
mboehme.github.io/paper/ICSE25... Really like this paper. Instead of writing a libfuzzer harness, use the state&arguments from test/E2E fuzzing and note what args can be fuzzed. Interesting follow ups: How to validate a crash in E2E setting & inferring amplification points & constraints dynamically.
mboehme.github.io
2121
Reposted by Cornelius Aschermann
dmnk @dmnk.bsky.social · 21/11/2024
Don't really know the purpose of starter packs yet, but here's some people who fuzz(ed). Let me know who I forgot go.bsky.app/EhGFSVj
2258
Reposted by Cornelius Aschermann
Hazel Weakly @hazelweakly.me · 19/11/2024
Company: We have a monolith! Me: ... Company: *holds up diagram of 8 services, 15 databases, and a home grown queue implementation* Me: You fucked up a perfectly good distributed system is what you did. Look at that thing, it's got clock skew.
1332238
Reposted by Cornelius Aschermann
Jascha Sohl-Dickstein @jascha.sohldickstein.com · 12/02/2024
Have you ever done a dense grid search over neural network hyperparameters? Like a *really dense* grid search? It looks like this (!!). Blueish colors correspond to hyperparameters for which training converges, redish to those for which training diverges. Even better, a video: vimeo.com/903855670
Examples of fractals resulting from neural network training in a variety of experimental configurations
714031
Reposted by Cornelius Aschermann
Paged Out! @pagedout.bsky.social · 19/11/2024
Paged Out! Issue #5 is out now! pagedout.institute?page=issues.... Happy reading!
05833