Post #1391
456
Channel Public Channel
AL Alaid TechThread
@offensive_thread
Vulnerability discovery, threat intelligence, reverse engineering, AppSec
- Subscribers
- 1.13K
- Photos
- 7
- Videos
- 2
- Links
- 1.4K
Showing posts older than #1392 · Back to latest
Older Posts 20 shown
Post #1390
478
What keeps kernel shadow stack effective against kernel exploits?
https://tandasat.github.io/blog/2025/04/02/sss.html
Satoshi’s notes What keeps kernel shadow stack effective against kernel exploits? This post introduces one of the virtualization features needed to keep kernel-mode shadow stack functional against kernel exploits: supervisor shadow stack restrictions / supervisor shadow-stack control. https://tandasat.github.io/blog/2025/04/02/sss.html
- 👍 2
Post #1389
442
AutoPatchBench, a benchmark for the automated repair of vulnerabilities identified through fuzzing
https://engineering.fb.com/2025/04/29/ai-research/autopatchbench-benchmark-ai-powered-security-fixes/
https://engineering.fb.com/2025/04/29/ai-research/autopatchbench-benchmark-ai-powered-security-fixes/
- 👍 3
- 🔥 2
Post #1388
418
Post #1387
422
OSVBench: Benchmarking LLMs on Specification Generation Tasks for
Operating System Verification
https://arxiv.org/pdf/2504.20964
Operating System Verification
https://arxiv.org/pdf/2504.20964
Post #1386
545
Large Language Model-Driven Concolic Execution
for Highly Structured Test Input Generation
https://arxiv.org/pdf/2504.17542
for Highly Structured Test Input Generation
https://arxiv.org/pdf/2504.17542
- 👍 1
Post #1385
442
Page-Oriented Programming: Subverting Control-Flow
Integrity of Commodity Operating System Kernels
with Non-Writable Code Pages
https://www.usenix.org/system/files/usenixsecurity24-han-seunghun.pdf
Integrity of Commodity Operating System Kernels
with Non-Writable Code Pages
https://www.usenix.org/system/files/usenixsecurity24-han-seunghun.pdf
- 🔥 3
Post #1384
566
A Framework for Evaluating Emerging Cyberattack Capabilities of AI by Google DeepMind
https://arxiv.org/pdf/2503.11917
https://arxiv.org/pdf/2503.11917
Post #1383
431
KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
https://i.blackhat.com/Asia-25/Asia-25-Ruan-KernJC.pdf
https://i.blackhat.com/Asia-25/Asia-25-Ruan-KernJC.pdf
Post #1382
588
2409.16165v2-2.pdf2.4 MB
Interactive Tools Substantially Assist LM Agents in Finding Security Vulnerabilities Post #1381
462
ghidraMCP is an Model Context Protocol server for allowing LLMs to autonomously reverse engineer applications. It exposes numerous tools from core Ghidra functionality to MCP clients.
https://github.com/LaurieWired/GhidraMCP
https://github.com/LaurieWired/GhidraMCP
- 🔥 3
Post #1380
447
Minimal LLM-based fuzz harness generator
https://adalogics.com/blog/minimal-llm-based-fuzz-harness-generator
https://adalogics.com/blog/minimal-llm-based-fuzz-harness-generator
- 👍 5
Post #1379
488
Exploit Development: Investigating Kernel Mode Shadow Stacks on Windows
https://connormcgarr.github.io/km-shadow-stacks/
Connor McGarr’s Blog Exploit Development: Investigating Kernel Mode Shadow Stacks on Windows Using SourcePoint’s JTAG debugger to investigate the implementation of Intel CET Shadow Stacks in kernel-mode on Windows https://connormcgarr.github.io/km-shadow-stacks/
- 🔥 3
Post #1378
955
The plugin provides a custom navigation interface within IDA. It examines execution paths from entry points, breaks down the binary into clusters of related functions, and highlights downstream behaviors and artifacts for quicker insights. XRefer can incorporate external data (e.g., API traces, capa results, user-defined xrefs) and provides path graphs for richer context. It integrates with Google's Gemini model to produce natural language descriptions of code relationships and behaviors. Additionally, XRefer can provide cluster based labels for functions, aiming to accelerate the manual static analysis process.
https://github.com/mandiant/xrefer
- 🔥 1
Post #1376
1.62K
8_Исправлять_—_не_искать_Роман_Лебедь_вер_2.pdf4.3 MB
Safeliner - AI решение для исправления уязвимостей в коде
#safeliner
#safeliner
- 👍 9
- 🔥 5
Post #1375
688
Leveling Up Fuzzing: Finding more vulnerabilities with AI
https://security.googleblog.com/2024/11/leveling-up-fuzzing-finding-more.html
Google Online Security Blog Leveling Up Fuzzing: Finding more vulnerabilities with AI Posted by Oliver Chang, Dongge Liu and Jonathan Metzman, Google Open Source Security Team Recently, OSS-Fuzz reported 26 new vulnerabilities... https://security.googleblog.com/2024/11/leveling-up-fuzzing-finding-more.html
- 🔥 1
Post #1374
590
Known Vulnerabilities of Open Source Projects: Where Are the Fixes?
https://ieeexplore.ieee.org/document/10381645
https://ieeexplore.ieee.org/document/10381645
- 👍 1
Post #1373
535
Fuzzing for complex bugs across languages in JavaScript Engines
https://powerofcommunity.net/poc2024/Carl%20Smith,%20Fuzzing%20for%20complex%20bugs%20across%20languages%20in%20JavaScript%20Engines.pdf
https://powerofcommunity.net/poc2024/Carl%20Smith,%20Fuzzing%20for%20complex%20bugs%20across%20languages%20in%20JavaScript%20Engines.pdf
- 🔥 1
Post #1372
487
Post #1371
612