Embedded-NUL handling in jq
Publicly credited vulnerability affecting jq through 1.8.1, fixed in 1.8.2. The site now points to the canonical record instead of overstating the affected path.
Canonical CVE record ↗Vulnerability research · validation systems · research infrastructure
I turn automated vulnerability leads into reproduced failures and fixes engineers can trust. I am not job hunting; this page measures which teams send a concrete offer anyway.
The labels mean different things on purpose
Every item is classified as reproduced, publicly credited, patched, or still private. That distinction matters more in 2026, when automated systems can produce findings faster than humans can validate and remediate them.
Publicly credited vulnerability affecting jq through 1.8.1, fixed in 1.8.2. The site now points to the canonical record instead of overstating the affected path.
Canonical CVE record ↗Candidate failures across C/C++ parsers and infrastructure software were rebuilt, pinned, and exercised under ASan or the native failure path. Unverified source-only claims do not make the count.
Fix verification reruns the original input against the patched build. A report is not done when it is filed; it is done when the failure no longer reproduces.
The most valuable failure
A conventional fuzzing campaign burned through 736 million executions and produced zero useful bugs. Hiding that would make the portfolio look better and the researcher look worse.
The response was FuzzLab: stop treating every target and method as equally valuable; track coverage, prerequisites, provenance, and prior yield; then schedule the next run deliberately.
Research operations, not a pile of shell scripts
FuzzLab coordinates repeatable adversarial methods across target sets, records what ran, normalizes heterogeneous findings, and makes blocked or stale work visible. Raw research data stays private; public claims are manually reviewed.
The field moved this year
Frontier systems are finding vulnerabilities at a scale that changes the job. The useful researcher is no longer just the person who can generate a lead; it is the person who can build a trustworthy path from lead to reproduced impact to fix.
OpenAI's Codex Security emphasizes threat-model context, isolated reproduction, and revalidation after remediation—not raw alert volume.
OpenAI announcement ↗Anthropic reported that AI-scale discovery shifted its limiting factor to verification, disclosure, and patching. That is a research-operations problem.
Project Glasswing update ↗EU Cyber Resilience Act vulnerability and incident reporting obligations begin for manufacturers of products with digital elements. This is context, not legal advice.
European Commission ↗How the work is judged
If the failure does not survive a pinned build and a concrete trigger, it does not enter the public count.
Tools, versions, hashes, exit states, and evidence paths matter more than a dramatic terminal capture.
Duplicates and failed hypotheses are removed. A smaller honest result set is a stronger artifact.
Undisclosed details stay private. Public technical depth should not create an avoidable exploit path.
The loop closes only after the original trigger no longer produces the failure.
The goal is a process that keeps producing high-signal work after the first clever result.
The experiment / no application attached
Send the actual opportunity. The experiment is deliberately strict so the result means something: exploratory recruiter messages are welcome conversations, but they are not counted as offers.