Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Trail of Bits

20 articles

Trail of Bits research 2d ago

Auditing in the age of (good enough) AI

Security firms have published numerous blog posts describing how they pointed their agent harness at a codebase and found dozens of bugs (we’re one of them)....

Trail of Bits → Details

Trail of Bits research 5d ago

1Password's AI patching benchmark is misleading

1Password’s FLAWED report, published on August 6, 2026, gives defenders a misleading picture of AI patching. Its headline says models produced clean fixes on...

Trail of Bits → Details

Trail of Bits research Sep 9

A “proof” of Fermat’s Last Theorem that fits the margin

Fermat famously claimed to have a “truly marvelous proof” of his Last Theorem, but he never wrote it down, insisting the margin of his page was too narrow to...

Trail of Bits → Details

Trail of Bits research Linux AMD Aug 26

VMs won't contain cyber-capable agents

As part of Patch the Planet, we received preview access to GPT 5.6-Cyber with a simple task: evaluate its cyber capabilities.

Trail of Bits → Details

Trail of Bits research Aug 25

State divergence enables unauthorized access

We found and reported a bug in Provenance Blockchain, a public proof-of-stake chain built on Cosmos SDK, that lets any user grant themselves admin control ov...

Trail of Bits → Details

Trail of Bits research Aug 11

How Trail of Bits helps verify the integrity of your Signal chats

Every Signal chat starts the same way: the client asks the Signal server for the public key associated with your contact’s phone number. But how do you know ...

Trail of Bits → Details

Trail of Bits research Amazon Aug 5

A few notes on AWS Nitro Enclaves: KMS integration

Nitro Enclaves and Key Management Service (KMS) feel like a natural fit: since the KMS can verify attestation documents generated by the enclaves, developers...

Trail of Bits → Details

Trail of Bits research Jul 30

Building secure Uniswap v4 hooks

Uniswap v4 hooks let developers add custom behavior to pools, including dynamic fees, custom accounting, and external integrations. This flexibility moves so...

Trail of Bits → Details

Trail of Bits research Jul 28

How we use /goal to find bugs in Patch the Planet

Codex’s /goal feature amplifies bug hunting, but getting good results requires the right prompt, the right scope, and the right number of outcomes per run. F...

Trail of Bits → Details

Trail of Bits research Jul 13

Rust-proof your code with our new Testing Handbook chapter

We’ve added a new chapter to our Testing Handbook: a comprehensive guide to security testing Rust programs. This chapter covers the tools and techniques we u...

Trail of Bits → Details

Trail of Bits research Jul 8

Mutation testing comes to DAML

In April we released Mewt, our open-source mutation-testing engine that finds the gaps in your test suite. Today we’re expanding it with support for DAML, th...

Trail of Bits → Details

Trail of Bits research Jul 2

GPT-5.5-Cyber built a zlib fuzzing lab in a day

We’re running Patch the Planet, an ongoing collaboration with OpenAI that pairs Trail of Bits engineers directly with more than 30 open-source projects. Its ...

Trail of Bits → Details

Trail of Bits research Jun 30

Shipping post-quantum cryptography to Python

Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency, we implemented support fo...

Trail of Bits → Details

Trail of Bits research Jun 22

Introducing Patch the Planet

What happens when you clear dozens of Trail of Bits engineers’ schedules, pair them with every open-source maintainer they can contact, and unleash the lates...

Trail of Bits → Details

Trail of Bits research Jun 12

Factoring "short-sleeve" RSA keys with polynomials

What happens when the bits of an RSA private key are heavily biased toward 0 instead of being randomly generated? The public key’s bits could be biased enoug...

Trail of Bits → Details

Trail of Bits research Cisco Jun 3

The sorry state of skill distribution

Public skill marketplaces are being flooded with malicious skills that steal credentials, exfiltrate data, and hijack agents. In response, a segment of the s...

T1041

Trail of Bits → Details

Trail of Bits research GitHub May 22

Bringing full YAML anchor support to zizmor

In March 2026, attackers exploited a pull_request_target misconfiguration in the aquasecurity/trivy-action GitHub Action to exfiltrate organization and repos...

T1041

Trail of Bits → Details

Trail of Bits research May 12

gosentry brings LibAFL-grade fuzzing to Go's native interface

Go’s native fuzzing is useful, but it stands far behind state-of-the-art tooling that the Rust, C, and C++ ecosystems offer with LibAFL and AFL++. Path const...

Trail of Bits → Details

Trail of Bits research Microsoft Linux May 5

Escalating a Windows driver registry bug to a kernel write primitive

We recently added a C/C++ security checklist to the Testing Handbook and challenged readers to spot the bugs in two code samples: a deceptively simple Linux ...

T1498

Trail of Bits → Details

Trail of Bits research Apr 29

Extending Ruzzy with LibAFL

LibAFL is all the rage in the fuzzing community these days, especially with LLVM’s libFuzzer being placed in maintenance mode. Written in Rust, LibAFL claims...

Trail of Bits → Details

1 2 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA