● Experiment open / August 2026 Not job hunting · concrete offers still count

Vulnerability research · validation systems · research infrastructure

Discovery is cheap now. Proof is not.

I turn automated vulnerability leads into reproduced failures and fixes engineers can trust. I am not job hunting; this page measures which teams send a concrete offer anyway.

Public record CVE-2026-33948 · jq embedded-NUL handling credited · fixed 1.8.2
11independently reproducedBuilt from source and exercised with a concrete trigger.
1public CVE creditAttribution is separated from independent reproduction.
2fixes verifiedThe same trigger was rerun against the patched build.
736Mexecutions that killed a thesisA zero-yield brute-force campaign became a systems lesson.
01 / Evidence

The labels mean different things on purpose

A crash is evidence. It is not automatically a discovery.

Every item is classified as reproduced, publicly credited, patched, or still private. That distinction matters more in 2026, when automated systems can produce findings faster than humans can validate and remediate them.

Public record / CVE-2026-33948

Embedded-NUL handling in jq

Publicly credited vulnerability affecting jq through 1.8.1, fixed in 1.8.2. The site now points to the canonical record instead of overstating the affected path.

Canonical CVE record ↗
Credited · fixed · public
Reproduction / memory safety

Real builds, real sanitizers

Candidate failures across C/C++ parsers and infrastructure software were rebuilt, pinned, and exercised under ASan or the native failure path. Unverified source-only claims do not make the count.

11 reproduced · sensitive details redacted
Remediation / regression

The trigger survives the report

Fix verification reruns the original input against the patched build. A report is not done when it is filed; it is done when the failure no longer reproduces.

2 patched outcomes verified
736M

The most valuable failure

More compute was not the answer.

A conventional fuzzing campaign burned through 736 million executions and produced zero useful bugs. Hiding that would make the portfolio look better and the researcher look worse.

The response was FuzzLab: stop treating every target and method as equally valuable; track coverage, prerequisites, provenance, and prior yield; then schedule the next run deliberately.

02 / FuzzLab

Research operations, not a pile of shell scripts

A closed loop for finding out what is actually true.

FuzzLab coordinates repeatable adversarial methods across target sets, records what ran, normalizes heterogeneous findings, and makes blocked or stale work visible. Raw research data stays private; public claims are manually reviewed.

01Inventory
02Prioritize
03Execute
04Normalize
05Reproduce
06Decide
Manifest-driven methodsExecution contracts are data, validated before a run starts.
Coverage-aware schedulingPrior history and missing prerequisites shape what runs next.
Normalized evidenceStructured JSON, output markers, and SARIF enter one finding pipeline.
Run provenanceMethod version, script hash, result summary, and exit state stay attached.
Honest blocked statesMissing source, harnesses, or corpora are reported instead of disguised.
Private by defaultNo live research database, raw paths, or undisclosed PoCs reach this site.
03 / Why now

The field moved this year

The scarce layer is verification, judgment, and closure.

Frontier systems are finding vulnerabilities at a scale that changes the job. The useful researcher is no longer just the person who can generate a lead; it is the person who can build a trustworthy path from lead to reproduced impact to fix.

06 MAR 2026

Validation became product infrastructure.

OpenAI's Codex Security emphasizes threat-model context, isolated reproduction, and revalidation after remediation—not raw alert volume.

OpenAI announcement ↗
22 MAY 2026

The bottleneck moved downstream.

Anthropic reported that AI-scale discovery shifted its limiting factor to verification, disclosure, and patching. That is a research-operations problem.

Project Glasswing update ↗
11 SEP 2026

Evidence has an operational deadline.

EU Cyber Resilience Act vulnerability and incident reporting obligations begin for manufacturers of products with digital elements. This is context, not legal advice.

European Commission ↗
04 / Operating system

How the work is judged

Signal over theater.

Reproduction over speculation

If the failure does not survive a pinned build and a concrete trigger, it does not enter the public count.

Provenance over screenshots

Tools, versions, hashes, exit states, and evidence paths matter more than a dramatic terminal capture.

Deletion over inflated metrics

Duplicates and failed hypotheses are removed. A smaller honest result set is a stronger artifact.

Disclosure over spectacle

Undisclosed details stay private. Public technical depth should not create an avoidable exploit path.

Fix verification over filing

The loop closes only after the original trigger no longer produces the failure.

Systems over heroics

The goal is a process that keeps producing high-signal work after the first clever result.

The experiment / no application attached

Think your team can make staying put feel irrational?

Send the actual opportunity. The experiment is deliberately strict so the result means something: exploratory recruiter messages are welcome conversations, but they are not counted as offers.

TeamRole + levelMandateLocation / remoteCompensation range
Make a qualifying offer