unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Auditing in the age of (good enough) AI
Security firms have published numerous blog posts describing how they pointed their agent harness at...
2026-9-18 11:0:0 | 阅读: 10 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
masm
miden
analysis
library
lean
1Password's AI patching benchmark is misleading
1Password’s FLAWED report, published on August 6, 2026, gives defenders a misleading picture of AI p...
2026-9-15 11:0:0 | 阅读: 14 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
agents
security
planet
maintainers
A “proof” of Fermat’s Last Theorem that fits the margin
Fermat famously claimed to have a “truly marvelous proof” of his Last Theorem, but he never wrote it...
2026-9-9 11:0:0 | 阅读: 26 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
lean
fermat
theorem
proofs
flt
VMs won't contain cyber-capable agents
As part of Patch the Planet, we received preview access to GPT 5.6-Cyber with a simple task: evaluat...
2026-8-26 11:0:0 | 阅读: 33 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
machine
security
upstream
software
gpt
State divergence enables unauthorized access
We found and reported a bug in Provenance Blockchain, a public proof-of-stake chain built on Cosmos...
2026-8-25 11:0:0 | 阅读: 22 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
marker
markers
attacker
provenance
How Trail of Bits helps verify the integrity of your Signal chats
Every Signal chat starts the same way: the client asks the Signal server for the public key associat...
2026-8-11 17:30:0 | 阅读: 28 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
client
auditor
auditors
trail
A few notes on AWS Nitro Enclaves: KMS integration
Nitro Enclaves and Key ManagementService (KMS) feel like anatural fit: since the KMS can verify at...
2026-8-5 11:0:0 | 阅读: 40 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
kms
enclave
cmk
enclaves
attestation
Building secure Uniswap v4 hooks
Uniswap v4 hooks let developers add custom behavior to pools, including dynamic fees, custom account...
2026-7-30 11:0:0 | 阅读: 42 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
poolmanager
accounting
fee
pools
attacker
How we use /goal to find bugs in Patch the Planet
Codex’s /goal feature amplifies bug hunting, but getting good results requires the right prompt, the...
2026-7-28 11:0:0 | 阅读: 46 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
codex
outcome
client
security
remote
Rust-proof your code with our new Testing Handbook chapter
We’ve added a new chapter to our Testing Handbook: a comprehensive guide to security testing Rust pr...
2026-7-13 11:0:0 | 阅读: 35 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
security
chapter
memory
analysis
reviews
Mutation testing comes to DAML
In April we released Mewt, our open-source mutation-testing engine that finds the gaps in your test...
2026-7-8 11:0:0 | 阅读: 35 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
daml
mewt
buyer
seller
mutants
Field reports from Patch the Planet
We’re running Patch the Planet, an ongoing collaboration with OpenAI that pairs Trail of Bits engine...
2026-7-2 11:0:0 | 阅读: 42 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
gpt
harness
zlib
maintainers
bespoke
Shipping post-quantum cryptography to Python
Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding...
2026-6-30 11:0:0 | 阅读: 41 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
dsa
kem
primitives
pyca
python
Introducing Patch the Planet
What happens when you clear dozens of Trail of Bits engineers’ schedules, pair them with every open-...
2026-6-22 16:50:0 | 阅读: 54 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
patchy
security
planet
python
maintainers
Factoring "short-sleeve" RSA keys with polynomials
What happens when the bits of an RSA private key are heavily biased toward 0 instead of being random...
2026-6-12 11:0:0 | 阅读: 57 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
sleeve
completeftp
polynomial
dsa
The sorry state of skill distribution
Public skill marketplaces are being flooded with malicious skills that steal credentials, exfiltrate...
2026-6-3 11:0:0 | 阅读: 62 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
skill
malicious
llm
scanners
We hardened zizmor's GitHub Actions static analyzer
In March 2026, attackers exploited a pull_request_target misconfiguration inthe aquasecurity/trivy-...
2026-5-22 11:0:0 | 阅读: 45 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
zizmor
anchor
github
workflows
anchors
Go fuzzing was missing half the toolkit. We forked the toolchain to fix it.
Go’s native fuzzing is useful, but it stands far behind state-of-the-art tooling that the Rust, C, a...
2026-5-12 11:0:0 | 阅读: 40 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
gosentry
digit
grammar
fuzzer
C/C++ checklist challenges, solved
We recently added a C/C++ security checklist to the Testing Handbook and challenged readers to spot...
2026-5-5 11:0:0 | 阅读: 57 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
readvalue
windows
Extending Ruzzy with LibAFL
LibAFL is all the rage in the fuzzing community these days, especially with LLVM’s libFuzzer being p...
2026-4-29 11:0:0 | 阅读: 44 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
ruzzy
libafl
fuzzer
libfuzzer
dummy
Previous
-1024
-1023
-1022
-1021
-1020
-1019
-1018
-1017
Next