CuraSec

tag: Fuzzing · 3 items

2026-08-10 · arXiv cs.CR · source ↗ #fuzzing#pdf-security#llm-research
  • Engineer — Learn: PDFuzzer’s LLM-guided API-sequence approach found zero-days ranging from info leakage to arbitrary code execution in Adobe Acrobat, Foxit, and PDF-XChange Editor; no CVEs, patches, or exploitation signals are present yet, so watch for vendor advisories following coordinated disclosure.
  • SOC/IR — Learn: No active exploitation, IOCs, or TTPs to hunt for; the finding that PDF reader JavaScript engines can be exploited via chained API calls is worth noting as a future detection surface if exploitation emerges.
  • Leader — Skip
  • Engineer — Learn: Novel research showing an LLM-agentic pipeline that improves directed fuzzer crash-trigger rates by generating semantically aware seed corpora; worth evaluating if your team runs fuzzing campaigns against internal C/C++ codebases, but no immediate change to running systems is required.
  • SOC/IR — Skip
  • Leader — Skip
2026-07-10 · HN (vulnerability) · source ↗ #fuzzing#appsec#research
  • Engineer — Learn: Practical walkthrough on building custom vulnerability harnesses — useful for teams doing fuzzing or exploit research, but no running-system change required today.
  • SOC/IR — Skip
  • Leader — Skip