Mayhem Blog

Expert insights and tips on application security, API security, and other DevSecOps topics.

View All
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Open Source Security Podcast EP. 151 - The DARPA Cyber Grand Challenge With David Brumley

Open Source Security Podcast EP. 151 - The DARPA Cyber Grand Challenge With David Brumley

Open Source Security Podcast helps listeners better understand security topics of the day. In this episode, David Brumley reflects on the ForAllSecure DARPA CGC win and how it offers a glimpse into the future of autonomous security.
Top 5 Takeaways From The “ForAllSecure Makes Software Security Automous” Livestream

Top 5 Takeaways From The “ForAllSecure Makes Software Security Automous” Livestream

In February 2019, Dr. David Brumley, ForAllSecure CEO, and Zach Walker, DIU project manager, discussed how Mayhem, ForAllSecure’s behavior testing solution, has helped secure the Department of Defense’s most critical platforms.
Onward To The Next Chapter In ForAllSecure's Journey

Onward To The Next Chapter In ForAllSecure's Journey

ForAllSecure raises $15M in series A funding, led by New Enterprise Associates.
A Reflection On ForAllSecure's Journey In Bootstrapping Behavior Testing Technology

A Reflection On ForAllSecure's Journey In Bootstrapping Behavior Testing Technology

Learn how we sought to uncover the right solution to address the persistent software security issues that have existed in the market for over two decades. We began our research in a university lab, where a brand new technology was born...
Innovators Under 35—Alex Rebert named to MIT Technology Review’s Annual List

Innovators Under 35—Alex Rebert named to MIT Technology Review’s Annual List

I am truly honored to share that I have been named to MIT Technology Review’s prestigious annual list of Innovators Under 35 as a Pioneer.
Applying Cyber Grand Challenge Technology To Real Software

Applying Cyber Grand Challenge Technology To Real Software

Looking at the history of reports, objdump was ripe for additional fuzzing enhanced by symbolic execution. Most of the bugs visible to existing fuzzing tools were already found and patched. If any more bugs were to be discovered by Mayhem, this would be a great indicator that Mayhem can find things other tools cannot.
Case Study: LEGIT_00004

Case Study: LEGIT_00004

LEGIT_00004 was a challenge from Defcon CTF that implemented a file system in memory. The intended bug was a tricky memory leak that the challenge author didn't expect Mayhem to get. However, Mayhem found an unintended null-byte overwrite bug that it leveraged to gain arbitrary code execution.
Mayhem Wins DARPA CGC

Mayhem Wins DARPA CGC

Mayhem is a fully autonomous system for finding and fixing computer security vulnerabilities. On Thursday, August 4, 2016, Mayhem competed in the historical DARPA Cyber Grand Challenge against other computers in a fully automatic hacking contest...and won.
Why CGC Matters To Me

Why CGC Matters To Me

Why am I excited about the DARPA Cyber Grand Challenge (CGC)? CGC gives the world, for the first time, an objective competition to measure how well different automated tools work on a level playing field.

Fancy some inbox Mayhem?

Subscribe to our monthly newsletter for expert insights and news on DevSecOps topics, plus Mayhem tips and tutorials.

By subscribing, you're agreeing to our website terms and privacy policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.