Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Google’s AI-powered OSS-Fuzz tool finds 26 vulnerabilities in open source projects
Global Security

Google’s AI-powered OSS-Fuzz tool finds 26 vulnerabilities in open source projects

AdminBy AdminNovember 21, 2024No Comments3 Mins Read
Open-Source Projects
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


November 21, 2024Ravi LakshmananArtificial Intelligence / Software Security

Open source projects

Google revealed that its AI-based fuzzing tool OSS-Fuzz was used to detect 26 vulnerabilities in various open-source repositories, including a medium-severity flaw in the OpenSSL cryptographic library.

“These specific vulnerabilities represent a major milestone for automated vulnerability discovery: each one was found using artificial intelligence using AI-generated and enhanced fuzz targets,” Google’s Open Source Security Team said in a blog post shared with The Hacker News.

OpenSSL vulnerability addressed CVE-2024-9143 (CVSS Score: 4.3), an out-of-memory write error that could cause an application or remote code execution to crash. There was a problem addressed in OpenSSL versions 3.3.3, 3.2.4, 3.1.8, 3.0.16, 1.1.1zb, and 1.0.2zl.

Cyber ​​security

Google that added the feature leverage large language models (LLM) to improve fuzzing coverage in OSS-Fuzz in August 2023, said the vulnerability has likely been present in the codebase for two decades and that it “would not have been detected with existing human-written fuzzing targets “.

In addition, the technology giant noted that the use of artificial intelligence to generate fluffy targets improved code coverage in 272 C/C++ projects by adding more than 370,000 lines of new code.

“One of the reasons that bugs like this can go undetected for so long is that line coverage is no guarantee that a feature is bug-free,” Google said. “Code coverage as a metric cannot measure all possible code paths and states—different flags and configurations can cause different behaviors, revealing different errors.”

These AI-assisted vulnerability detections are also made possible by LLMs proving adept at emulating a developer’s workflow, allowing for more automation.

The development is in line with the company revealed Earlier this month, his LLM-based framework called Big Sleep contributed to the discovery of a zero-day vulnerability in the open source SQLite database engine.

In tandem, Google is working on this transitory own code bases memory-safe languages such as Rust, while also modernizing mechanisms to address spatial memory security vulnerabilities – which occur when a piece of code can access memory that is outside of its intended boundaries – in existing C++ projects, including Chrome.

Cyber ​​security

This includes migrating to Safe buffers and allows fixed libc++which adds bounds checking to standard C++ data structures to address a significant class of spatial safety bugs. In addition, the overhead incurred as a result of incorporating the change was noted to be minimal (ie, on average 0.30% performance impact).

“The hardened libc++ library, recently added by open source contributors, provides a set of security checks designed to detect vulnerabilities such as out-of-bounds in production” Google said. “While C++ will not become completely memory-safe, these improvements reduce the risk (…), resulting in more robust and secure software.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025

Fedramp at starting speed: obtained lessons

June 18, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025

Fedramp at starting speed: obtained lessons

June 18, 2025

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.