unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
A “proof” of Fermat’s Last Theorem that fits the margin
Fermat famously claimed to have a “truly marvelous proof” of his Last Theorem, but he never wrote it...
2026-9-9 11:0:0 | 阅读: 8 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
lean
fermat
theorem
proofs
flt
VMs won't contain cyber-capable agents
As part of Patch the Planet, we received preview access to GPT 5.6-Cyber with a simple task: evaluat...
2026-8-26 11:0:0 | 阅读: 29 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
machine
security
upstream
software
gpt
State divergence enables unauthorized access
We found and reported a bug in Provenance Blockchain, a public proof-of-stake chain built on Cosmos...
2026-8-25 11:0:0 | 阅读: 20 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
marker
markers
attacker
provenance
How Trail of Bits helps verify the integrity of your Signal chats
Every Signal chat starts the same way: the client asks the Signal server for the public key associat...
2026-8-11 17:30:0 | 阅读: 24 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
client
auditor
auditors
trail
A few notes on AWS Nitro Enclaves: KMS integration
Nitro Enclaves and Key ManagementService (KMS) feel like anatural fit: since the KMS can verify at...
2026-8-5 11:0:0 | 阅读: 36 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
kms
enclave
cmk
enclaves
attestation
Building secure Uniswap v4 hooks
Uniswap v4 hooks let developers add custom behavior to pools, including dynamic fees, custom account...
2026-7-30 11:0:0 | 阅读: 37 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
poolmanager
accounting
fee
pools
attacker
How we use /goal to find bugs in Patch the Planet
Codex’s /goal feature amplifies bug hunting, but getting good results requires the right prompt, the...
2026-7-28 11:0:0 | 阅读: 42 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
codex
outcome
client
security
remote
Rust-proof your code with our new Testing Handbook chapter
We’ve added a new chapter to our Testing Handbook: a comprehensive guide to security testing Rust pr...
2026-7-13 11:0:0 | 阅读: 31 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
security
chapter
memory
analysis
reviews
Mutation testing comes to DAML
In April we released Mewt, our open-source mutation-testing engine that finds the gaps in your test...
2026-7-8 11:0:0 | 阅读: 31 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
daml
mewt
buyer
seller
mutants
Field reports from Patch the Planet
We’re running Patch the Planet, an ongoing collaboration with OpenAI that pairs Trail of Bits engine...
2026-7-2 11:0:0 | 阅读: 40 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
gpt
harness
zlib
maintainers
bespoke
Shipping post-quantum cryptography to Python
Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding...
2026-6-30 11:0:0 | 阅读: 36 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
dsa
kem
primitives
pyca
python
Introducing Patch the Planet
What happens when you clear dozens of Trail of Bits engineers’ schedules, pair them with every open-...
2026-6-22 16:50:0 | 阅读: 42 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
patchy
security
planet
python
maintainers
Factoring "short-sleeve" RSA keys with polynomials
What happens when the bits of an RSA private key are heavily biased toward 0 instead of being random...
2026-6-12 11:0:0 | 阅读: 51 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
sleeve
completeftp
polynomial
dsa
The sorry state of skill distribution
Public skill marketplaces are being flooded with malicious skills that steal credentials, exfiltrate...
2026-6-3 11:0:0 | 阅读: 61 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
skill
malicious
llm
scanners
We hardened zizmor's GitHub Actions static analyzer
In March 2026, attackers exploited a pull_request_target misconfiguration inthe aquasecurity/trivy-...
2026-5-22 11:0:0 | 阅读: 44 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
zizmor
anchor
github
workflows
anchors
Go fuzzing was missing half the toolkit. We forked the toolchain to fix it.
Go’s native fuzzing is useful, but it stands far behind state-of-the-art tooling that the Rust, C, a...
2026-5-12 11:0:0 | 阅读: 38 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
gosentry
digit
grammar
fuzzer
C/C++ checklist challenges, solved
We recently added a C/C++ security checklist to the Testing Handbook and challenged readers to spot...
2026-5-5 11:0:0 | 阅读: 54 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
readvalue
windows
Extending Ruzzy with LibAFL
LibAFL is all the rage in the fuzzing community these days, especially with LLVM’s libFuzzer being p...
2026-4-29 11:0:0 | 阅读: 43 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
ruzzy
libafl
fuzzer
libfuzzer
dummy
Trailmark turns code into graphs
嗯,用户让我用中文总结这篇文章,控制在100字以内,而且不需要特定的开头。首先,我需要快速浏览文章内容,抓住主要信息。 文章主要介绍了Trailmark这个开源库,它能把源代码解析成可查询的调用图,通过Python API供Claude技能使用。然后提到了它的功能,比如分析代码结构、处理多种编程语言、支持各种安全分析技能等。 接下来,用户可能需要一个简洁明了的总结,突出Trailmark的作用和优势。我应该涵盖它如何帮助分析代码安全问题,比如识别等效突变、检测架构瓶颈等。 最后,确保总结在100字以内,并且直接描述文章内容,不使用“这篇文章”之类的开头。 </think> Trailmark 是一个开源库,将源代码解析为可查询的调用图,并通过 Python API 供 Claude 技能使用。它支持 17 种编程语言,用于分析代码结构、识别安全风险、处理突变测试和生成测试向量等。该工具帮助开发者更高效地发现代码中的潜在问题,并提供多种技能扩展功能。...
2026-4-23 12:0:0 | 阅读: 47 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
trailmark
claude
mutation
mutants
analysis
We beat Google’s zero-knowledge proof of quantum cryptanalysis
嗯,用户让我总结这篇文章的内容,控制在一百个字以内,而且不需要特定的开头。首先,我需要快速浏览文章,抓住主要信息。 文章讲的是Google的量子AI团队发布了一个零知识证明,优化了量子电路,声称第一代量子计算机可以在9分钟内破解椭圆曲线加密。然后Trail of Bits团队改进了这个证明,并发现了Google代码中的漏洞。他们利用内存安全和逻辑漏洞伪造了证明,但Google已经修复了问题。 总结时要包括:Google的优化、Trail of Bits的改进、利用漏洞、以及修复情况。同时要简洁明了,不超过100字。 可能的结构是:Google优化量子电路... Trail of Bits改进并发现漏洞... Google修复... 这样就能涵盖主要点,并且符合用户的要求。 </think> Google优化量子电路以9分钟破解椭圆曲线加密,Trail of Bits团队通过发现并利用其Rust代码中的内存安全和逻辑漏洞改进了该证明,并伪造了一个看似更优的零知识证明。Google已修复漏洞,但事件凸显零知识证明系统的独特攻击面。...
2026-4-17 11:0:0 | 阅读: 42 |
收藏
|
Trail of Bits Blog - blog.trailofbits.com
circuit
qubit
qubits
toffoli
gates
Previous
-659
-658
-657
-656
-655
-654
-653
-652
Next