Mayhem Blog

Expert insights and tips on application security, API security, and other DevSecOps topics.

View All
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
The Hacker Mind Podcast: Stopping the Mirai IoT Botnet, One CnC Server At A Time

The Hacker Mind Podcast: Stopping the Mirai IoT Botnet, One CnC Server At A Time

In 2016, the Mirai IoT botnet shut down part of the internet, yet variations still plague us today. Maybe our current approach to IoT botnets isn’t working? Ali Davanian and Ahmad Darki join the Hacker Mind podcast to discuss their Black Hat USA 2021 talk and their tool, CnCHunter.
Generating a Tiny Test Suite with Greedy Set Cover Minimization

Generating a Tiny Test Suite with Greedy Set Cover Minimization

No one likes waiting for regression tests to run.  Maintaining the smallest regression test suite that still covers all the code makes sure your software pipeline is as fast as possible.  In addition, when running a fuzzing campaign to find bugs, a smaller initial test suite (aka "corpus" or "seeds") typically improves fuzzing efficiency. In this article, we describe an algorithm that gives you a 2.7x improvement.
The FuzzCon 2021 Real Talks Panel

The FuzzCon 2021 Real Talks Panel

In August 2021, Dr James Ransome hosted the Fuzzing Real Talks at FuzzCon 2021. Ransome was joined by industry experts Anmol Misra of Autodesk, Larry Maccherone of Contract Security, Damilare D. Fagbemi of Resilient Software Security, and Jeff Costlow of Extrahop Networks.
Fuzz in Your Language, Fuzzer, or Architecture!

Fuzz in Your Language, Fuzzer, or Architecture!

At ForAllSecure, we’re all about fuzzing and making it easier for customers to quickly fuzz and secure their applications. That’s why we’ve gone ahead and compiled a catalog of tutorial fuzzing targets written and compiled using several different languages (and architectures) like C/C++, Python, Go, Rust, Java and many others!
The Fundamentals of Fuzz Testing

The Fundamentals of Fuzz Testing

Organizations are increasingly adopting more security practices to ensure the quality and robustness of their applications. One of the challenges that remain unaddressed is finding unknown or zero-day vulnerabilities.
The Hacker Mind Podcast: Surviving Stalkerware

The Hacker Mind Podcast: Surviving Stalkerware

What role does technology play in facilitating intimate partner abuse? What role might the security industry have in identifying or even stopping it? Ludrina Cherne and Martijn Grooten join the The Hacker Mind podcast to discuss their 2021 Black Hat USA talk.
Can Application Security Testing Be Fixed?

Can Application Security Testing Be Fixed?

In August 2021, Brook S. E. Shoenfield -- Author, Passionate Security Architect, and Curious Questioner of Assumptions -- challenged whether application security can be fixed at FuzzCon 2021. Shoenfield observed and boldly called out that breaches not only continue to roll in, but the cadence continues to increase.
The Hacker Mind Podcast: Learn Competitive Hacking with picoCTF

The Hacker Mind Podcast: Learn Competitive Hacking with picoCTF

PPP wanted to give their past high school selves the infosec education they didn’t have. But if you think picoCTF is only for HS students, think again.
FuzzCon 2021 Addresses Ease-of-Use in Fuzz Testing

FuzzCon 2021 Addresses Ease-of-Use in Fuzz Testing

Last August 2021, ForAllSecure held its second annual FuzzCon. FuzzCon seeks to bring together technical experts and industry leaders across various sectors to share fuzz testing knowledge. Our ultimate vision for FuzzCon is to be a key source for connecting people with knowledge and fellow enthusiasts.

Fancy some inbox Mayhem?

Subscribe to our monthly newsletter for expert insights and news on DevSecOps topics, plus Mayhem tips and tutorials.

By subscribing, you're agreeing to our website terms and privacy policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.