Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Trail of Bits

20 articles

Trail of Bits research 1d ago

Building secure Uniswap v4 hooks

Uniswap v4 hooks let developers add custom behavior to pools, including dynamic fees, custom accounting, and external integrations. This flexibility moves so...

Trail of Bits → Details

Trail of Bits research 3d ago

How we use /goal to find bugs in Patch the Planet

Codex’s /goal feature amplifies bug hunting, but getting good results requires the right prompt, the right scope, and the right number of outcomes per run. F...

Trail of Bits → Details

Trail of Bits research Jul 13

Rust-proof your code with our new Testing Handbook chapter

We’ve added a new chapter to our Testing Handbook: a comprehensive guide to security testing Rust programs. This chapter covers the tools and techniques we u...

Trail of Bits → Details

Trail of Bits research Jul 8

Mutation testing comes to DAML

In April we released Mewt, our open-source mutation-testing engine that finds the gaps in your test suite. Today we’re expanding it with support for DAML, th...

Trail of Bits → Details

Trail of Bits research Jul 2

GPT-5.5-Cyber built a zlib fuzzing lab in a day

We’re running Patch the Planet, an ongoing collaboration with OpenAI that pairs Trail of Bits engineers directly with more than 30 open-source projects. Its ...

Trail of Bits → Details

Trail of Bits research Jun 30

Shipping post-quantum cryptography to Python

Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency, we implemented support fo...

Trail of Bits → Details

Trail of Bits research Jun 22

Introducing Patch the Planet

What happens when you clear dozens of Trail of Bits engineers’ schedules, pair them with every open-source maintainer they can contact, and unleash the lates...

Trail of Bits → Details

Trail of Bits research Jun 12

Factoring "short-sleeve" RSA keys with polynomials

What happens when the bits of an RSA private key are heavily biased toward 0 instead of being randomly generated? The public key’s bits could be biased enoug...

Trail of Bits → Details

Trail of Bits research Cisco Jun 3

The sorry state of skill distribution

Public skill marketplaces are being flooded with malicious skills that steal credentials, exfiltrate data, and hijack agents. In response, a segment of the s...

T1041

Trail of Bits → Details

Trail of Bits research GitHub May 22

Bringing full YAML anchor support to zizmor

In March 2026, attackers exploited a pull_request_target misconfiguration in the aquasecurity/trivy-action GitHub Action to exfiltrate organization and repos...

T1041

Trail of Bits → Details

Trail of Bits research May 12

gosentry brings LibAFL-grade fuzzing to Go's native interface

Go’s native fuzzing is useful, but it stands far behind state-of-the-art tooling that the Rust, C, and C++ ecosystems offer with LibAFL and AFL++. Path const...

Trail of Bits → Details

Trail of Bits research Microsoft Linux May 5

Escalating a Windows driver registry bug to a kernel write primitive

We recently added a C/C++ security checklist to the Testing Handbook and challenged readers to spot the bugs in two code samples: a deceptively simple Linux ...

T1498

Trail of Bits → Details

Trail of Bits research Apr 29

Extending Ruzzy with LibAFL

LibAFL is all the rage in the fuzzing community these days, especially with LLVM’s libFuzzer being placed in maintenance mode. Written in Rust, LibAFL claims...

Trail of Bits → Details

Trail of Bits research Apr 23

Trailmark turns code into graphs

We’re open-sourcing Trailmark, a library that parses source code into a queryable call graph of functions, classes, call relationships, and semantic metadata...

Trail of Bits → Details

Trail of Bits research Google Apr 17

We beat Google’s zero-knowledge proof of quantum cryptanalysis

Two weeks ago, Google’s Quantum AI group published a zero-knowledge proof of a quantum circuit so optimized, they concluded that first-generation quantum com...

Trail of Bits → Details

Trail of Bits research Microsoft Linux Apr 9

Master C and C++ with our new Testing Handbook chapter

We added a new chapter to our Testing Handbook: a comprehensive security checklist for C and C++ code. We’ve identified a broad range of common bug classes, ...

Trail of Bits → Details

Trail of Bits research SAP Apr 7

What we learned about TEE security from auditing WhatsApp's Private Inference

WhatsApp’s new “Private Inference” feature represents one of the most ambitious attempts to combine end-to-end encryption with AI-powered capabilities, such ...

Trail of Bits → Details

Trail of Bits research Apr 3

Simplifying MBA obfuscation with CoBRA

Mixed Boolean-Arithmetic (MBA) obfuscation disguises simple operations like x + y behind tangles of arithmetic and bitwise operators. Malware authors and sof...

T1027 T1598

Trail of Bits → Details

Trail of Bits research Apr 1

Mutation testing for the agentic era

Code coverage is one of the most dangerous quality metrics in software testing. Many developers fail to realize that code coverage lies by omission: it measu...

Trail of Bits → Details

Trail of Bits research Mar 31

How we made Trail of Bits AI-native (so far)

This post is adapted from a talk I gave at [un]prompted, the AI security practitioner conference. Thanks to Gadi Evron for inviting me to speak.

Trail of Bits → Details

1 2 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA