#VulnResearch
New video out!

Security analyst John Ostrowski show the hands-on process behind discovering CVE-2025-24076 and CVE-2025-24994 described in our recent blog post.

Watch here: youtu.be/YwNcTuHxnAI

#security #pentest #windowsinternals #vulnresearch
300 Milliseconds to Admin: Mastering DLL Hijacking and Hooking to Win the Race
YouTube video by Compass Security
youtu.be
December 2, 2025 at 9:45 AM
Boom! 💥
Windows Hello fingerprint authentication bypassed on top three devices:
- Dell Inspiron
- Lenovo ThinkPad
- Microsoft Surface Pro
Still waiting for recordings from our BlueHat talk to drop, but here's our writeup: blackwinghq.com/blog/posts/a...
#infosec #security #vulnresearch
A Touch of Pwn - Part I
Blackwing Intelligence provides high-end security engineering, analysis, and research services for engineering focused organizations
blackwinghq.com
November 21, 2023 at 7:49 PM
Quote of the day: "Nicely done. It doesn’t undo all the (often rightly deserved) bad press that AI agents have received lately, but good news is good news."

www.vice.com/en/article/g...

#BigSleep #VulnResearch
Google's 'Big Sleep' Just Became the First-Ever AI to Prevent a Cyberattack
Google's Big Sleep is just a year old, and for the first time it as able to detect and help close a vulnerability at risk of being exploited.
www.vice.com
July 19, 2025 at 1:25 AM
I've done some work in the past year with AI security startups focused on leveraging AI to find vulns. Their results were impressive.

This is running out-of-the-box without any add-on knowledge/expertise and is even more impressive in results.

#AI #vulnresearch

www.axios.com/2026/02/05/a...
Anthropic's newest AI model uncovered 500 zero-day software flaws in testing
The AI company sees the model's advancements as a major win for cyber defenders in the race against adversarial AI.
www.axios.com
February 5, 2026 at 10:00 PM
My favorite debugger output is the kind that ruins a confident theory.

#exploitdev #BinaryExploitation #VulnResearch #AppSec #InfoSec
September 10, 2026 at 7:58 PM
A crash is not a failure. It is the program explaining its boundaries.

#exploitdev #BinaryExploitation #VulnResearch #AppSec #InfoSec
September 2, 2026 at 2:06 PM
I don't collect CVEs. I collect lessons from how assumptions fail.
#ExploitDev #VulnResearch #CyberSecurity #AppSec
August 29, 2026 at 7:51 PM
Crucial point: PoC (Proof of Concept) is needed BEFORE GTFO. Validate LLM-suggested vulnerabilities with a working exploit to avoid spreading false positives. #VulnResearch 5/6
May 25, 2025 at 6:00 PM
~Trailofbits~
GPT-5.5-Cyber autonomously built a bespoke fuzzing harness for zlib in a day, finding several bugs and eroding the expertise barrier for attackers.
-
IOCs: (None identified)
-
#AI #ThreatIntel #VulnResearch
Field reports from Patch the Planet
blog.trailofbits.com
July 2, 2026 at 12:51 PM
~Projectzero~
Google Project Zero details flaws in mutational grammar fuzzing and proposes a hybrid generative-mutational approach to improve bug discovery.
-
IOCs: (None identified)
-
#Fuzzing #ThreatIntel #VulnResearch
Effectiveness of Mutational Grammar Fuzzing
projectzero.google
March 19, 2026 at 8:20 PM