
Oliver Chang
@halbecaf
halbecaf.bsky.social
Senior Staff Eng @ Google Open Source Security. Founder of OSV.dev, lead/co-founder for OSS-Fuzz.
ID: 740795131234770944
09-06-2016 06:38:17
194 Tweet
1,1K Followers
143 Following









The OSS-Fuzz team at GoogleĀ is using AI-powered fuzzing to find vulns in open-source software and recently reported 26 new vulns to open-source project maintainers, including one in the OpenSSL library which is critical to most internet infrastructure. security.googleblog.com/2024/11/leveliā¦

New blog post about OSS-Fuzz AI-powered fuzzing is live! We talk about what went into making LLMs work well enough for this use case to find 26 new vulnerabilities (including a CVE in OpenSSL), as well as what else we have planned to make this better. security.googleblog.com/2024/11/leveliā¦

On the heels of Googleās āBig Sleepā AI discovery of a real-world vulnerability, our OSS-Fuzz team identified and reported 26 vulnerabilities to open-source project maintainers by using AI-generated and enhanced fuzz targets. Read more here: security.googleblog.com/2024/11/leveliā¦



Today, we announced the official release of OSV-SCALIBR, Google's software composition analysis library. If you are working in vuln management / security scanning, SCALIBR is for you! SCALIBR is powering most of Google's vuln scanning. Please RT security.googleblog.com/2025/01/osv-scā¦



šInviting GSoC2025 contributors to supercharge OSS-Fuzz-Gen! Opportunities include:ā 1. Modularize OSS-Fuzz āfeatures 2. Enhance Experiment Execution & Report UIā 3. Integrate Research Innovationsā Interested? Send your resume to [email protected]š gist.github.com/dynamicwebpaigā¦