Mayhem Blog
Code Security

Generating a Tiny Test Suite with Greedy Set Cover Minimization
No one likes waiting for regression tests to run. Maintaining the smallest regression test suite that still covers all the code makes sure your software pipeline is as fast as possible. In addition, when running a fuzzing campaign to find bugs, a smaller initial test suite (aka "corpus" or "seeds") typically improves fuzzing efficiency. In this article, we describe an algorithm that gives you a 2.7x improvement.

The FuzzCon 2021 Real Talks Panel
In August 2021, Dr James Ransome hosted the Fuzzing Real Talks at FuzzCon 2021. Ransome was joined by industry experts Anmol Misra of Autodesk, Larry Maccherone of Contract Security, Damilare D. Fagbemi of Resilient Software Security, and Jeff Costlow of Extrahop Networks.

Fuzz in Your Language, Fuzzer, or Architecture!
At ForAllSecure, we’re all about fuzzing and making it easier for customers to quickly fuzz and secure their applications. That’s why we’ve gone ahead and compiled a catalog of tutorial fuzzing targets written and compiled using several different languages (and architectures) like C/C++, Python, Go, Rust, Java and many others!

Can Application Security Testing Be Fixed?
In August 2021, Brook S. E. Shoenfield -- Author, Passionate Security Architect, and Curious Questioner of Assumptions -- challenged whether application security can be fixed at FuzzCon 2021. Shoenfield observed and boldly called out that breaches not only continue to roll in, but the cadence continues to increase.

Fuzzing with Biden's Executive Order 14028
Following Biden's Executive Order 14028, the National Institute of Standards and Technology (NISA) published the minimum recommendations for verification of code by developers. Mayhem can help both security engineers and developers validate many of these techniques.
Add Mayhem to Your DevSecOps for Free.
.jpg)