Everything you care about in one place

Follow feeds: blogs, news, RSS and more. An effortless way to read and digest content of your choice.

Get Feeder

blog.trailofbits.com

Trail of Bits Blog

Get the latest updates from Trail of Bits Blog directly as they happen.

Follow now 659 followers

Latest posts

Last updated about 2 hours ago

Balancer hack analysis and guidance for the DeFi ecosystem

about 3 hours ago

TL;DR The root cause of the hack was a rounding direction issue...

The cryptography behind electronic passports

8 days ago

Did you know that most modern passports are actually embedded devices containing...

Vulnerabilities in LUKS2 disk encryption for confidential VMs

9 days ago

Trail of Bits is disclosing vulnerabilities in eight different confidential computing systems...

Prompt injection to RCE in AI agents

17 days ago

We bypassed human approval protections for system command execution in AI agents...

Taming 2,500 compiler warnings with CodeQL, an OpenVPN2 case study

about 1 month ago

We created a CodeQL query that reduced 2,500+ compiler warnings about implicit...

Supply chain attacks are exploiting our assumptions

about 1 month ago

Supply chain attacks exploit fundamental trust assumptions in modern software development, from...

Use mutation testing to find the bugs your tests don't catch

about 2 months ago

Mutation testing reveals blind spots in test suites by systematically introducing bugs...

Fickling’s new AI/ML pickle file scanner

about 2 months ago

We’ve added a pickle file scanner to Fickling that uses an allowlist...

How Sui Move rethinks flash loan security

about 2 months ago

Sui’s Move language significantly improves flash loan security by replacing Solidity’s reliance...

Safer cold storage on Ethereum

2 months ago

By using smart contract programmability, exchanges can build custody solutions that remain...

Subverting code integrity checks to locally backdoor Signal, 1Password, Slack, and more

2 months ago

A vulnerability in Electron applications allows attackers to bypass code integrity checks...

Intern projects that outlived the internship

2 months ago

Our business operations intern at Trail of Bits built two AI-powered tools...