Mayhem Blog

Jeff Moss on the Evolution of Hacking at SecTor 2021

Jeff Moss on the Evolution of Hacking at SecTor 2021

Jeff Moss, CSO ICANN and founder of DEF CON/Black Hat, gave the keynote speech at this year's SecTor in Toronto, Ontario, reflecting on the evolution of hacking.
Generating a Tiny Test Suite with Greedy Set Cover Minimization

Generating a Tiny Test Suite with Greedy Set Cover Minimization

No one likes waiting for regression tests to run.  Maintaining the smallest regression test suite that still covers all the code makes sure your software pipeline is as fast as possible.  In addition, when running a fuzzing campaign to find bugs, a smaller initial test suite (aka "corpus" or "seeds") typically improves fuzzing efficiency. In this article, we describe an algorithm that gives you a 2.7x improvement.
The FuzzCon 2021 Real Talks Panel

The FuzzCon 2021 Real Talks Panel

In August 2021, Dr James Ransome hosted the Fuzzing Real Talks at FuzzCon 2021. Ransome was joined by industry experts Anmol Misra of Autodesk, Larry Maccherone of Contract Security, Damilare D. Fagbemi of Resilient Software Security, and Jeff Costlow of Extrahop Networks.
Fuzz in Your Language, Fuzzer, or Architecture!

Fuzz in Your Language, Fuzzer, or Architecture!

At ForAllSecure, we’re all about fuzzing and making it easier for customers to quickly fuzz and secure their applications. That’s why we’ve gone ahead and compiled a catalog of tutorial fuzzing targets written and compiled using several different languages (and architectures) like C/C++, Python, Go, Rust, Java and many others!
The Fundamentals of Fuzz Testing

The Fundamentals of Fuzz Testing

Organizations are increasingly adopting more security practices to ensure the quality and robustness of their applications. One of the challenges that remain unaddressed is finding unknown or zero-day vulnerabilities.
Can Application Security Testing Be Fixed?

Can Application Security Testing Be Fixed?

In August 2021, Brook S. E. Shoenfield -- Author, Passionate Security Architect, and Curious Questioner of Assumptions -- challenged whether application security can be fixed at FuzzCon 2021. Shoenfield observed and boldly called out that breaches not only continue to roll in, but the cadence continues to increase.
Fuzzing with Biden's Executive Order 14028

Fuzzing with Biden's Executive Order 14028

Following Biden's Executive Order 14028, the National Institute of Standards and Technology (NISA) published the minimum recommendations for verification of code by developers. Mayhem can help both security engineers and developers validate many of these techniques.
Good, Better, Best Software Testing Tools

Good, Better, Best Software Testing Tools

What are the defenses that we have against the software vulnerabilities?
Jen Easterly Takes Charge of CISA At Black Hack USA 2021

Jen Easterly Takes Charge of CISA At Black Hack USA 2021

The new Director of the Cybersecurity and Infrastructure Security Agency (CISA), Jen Easterly, opened Day 2 of Black Hat USA 2021 with a remote presentation on Hacking the Cybersecurity Puzzle.

Fancy some inbox Mayhem?

Subscribe to our monthly newsletter for expert insights and news on DevSecOps topics, plus Mayhem tips and tutorials.

By subscribing, you're agreeing to our website terms and privacy policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.