
stefan avgoustakis
4.8K posts

stefan avgoustakis
@savgoust
Cloud Security stuff @Googlecloud | Opinions = mine





This week we've added another 8 trophies to OSS-Fuzz-Gen (for a total of 14)! These are vulnerabilities found by LLM-generated harnesses. The interesting bit here is many of these are in well-fuzzed projects with thousands of hours of fuzzing already. #bugs-discovered" target="_blank" rel="nofollow noopener">github.com/google/oss-fuz…


I'd like to express too my gratitude to the OSV team at Google 💌, @halbecaf, Andrew Pollock, and Charl de Nysschen. Their announcement note below in this same thread. Read all about this news here chainguard.dev/unchained/chai…









This is a wake up reminder that you shouldn’t have an internet connected privileged binary running on your production systems. What was a bad update could have easily been a massive adversary backdoor. A third party vendor will always be the weakest link. Isolate critical systems


Google nearing a deal to acquire Wiz is likely FALSE! I'm chatting with Wiz in a few days, and I don't think this would happen. Also can't explain the integration with GCP. "IF" it happens, would be a big step by $GOOGL to level up their lacklustre participation in cybersecurity. They've severely lagged $MSFT & $AMZN! Would also be a big threat to $PANW & $CRWD!



