Skip to content

Tags

vulnerability-research

10 min read

Grammar-Based Fuzzing: What Random Mutation Misses

Why random-mutation fuzzers lose coverage on structured protocols, and how to model a PDU with a grammar to systematically traverse field combinations. Covers And/Or combinatorial-explosion control, automatic boundary-value generation, automatic Size-field computation, and Lua-based checksum recomputation.

Read full article
11 min read

An LLM Doesn't Know Whether It Finished — Designing a Harness That Moves the Completion Verdict Outside the Model

Multiple studies conclude that an LLM agent's completion bias and overconfidence cannot be corrected by prompting. This post lays out the design principles of a vulnerability-checking automation harness that makes "surveyed everything" and "0 vulnerabilities" computed from an HMAC receipt ledger and deterministic hooks rather than from the model's narrative. A "200 OK" without a negative control is not confirmation.

Read full article
19 min read

Anatomy of Achilles Certification — How Industrial Control Devices Get Fuzzed

An anatomy of how Achilles Communications Certification (ACC) tests PLCs, RTUs, and industrial switches. It covers the classification of 31 L1 / 54 L2 test cases, the seven test types (Scans, Storms, Fuzzers, Grammars), control-protocol coverage from the IP stack up to DNP3, Modbus, and IEC 61850, and what the Normal/Warning/Failure monitors actually determine.

Read full article
12 min read

AI Security Agent Architecture: From Reconnaissance to Exploitation

The architecture of a hierarchical multi-agent system that performs autonomous vulnerability assessment, from network reconnaissance to exploit validation. Seven specialists, a five-phase workflow, and the confirmation oracle, execution isolation, and RoE reference monitor that pull the judgment authority out of the model.

Read full article
10 min read

Fuzzer Design for LS Electric PLC Protocol Analysis

A draft design for blackbox fuzzing of the LS Electric PLC system, built on analysis of the XGT protocol. Covers automated mutation strategy, crash triage, and the monitoring infrastructure for discovering vulnerabilities in industrial control systems.

Read full article