<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Code Intelligence Blog</title>
    <link>https://www.code-intelligence.com/blog</link>
    <description>Learn more about the latest trends in fuzzing and software security testing in the new Code Intelligence blog.</description>
    <language>en</language>
    <pubDate>Thu, 12 Jun 2025 14:13:13 GMT</pubDate>
    <dc:date>2025-06-12T14:13:13Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>AI-automated Fuzzing Uncovers Two More Vulnerabilities in wolfSSL</title>
      <link>https://www.code-intelligence.com/blog/ai-automated-fuzz-test-uncovers-vulnerabilities-in-wolfssl</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.code-intelligence.com/blog/ai-automated-fuzz-test-uncovers-vulnerabilities-in-wolfssl" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.code-intelligence.com/hubfs/wolfssl%202.png" alt="AI-automated Fuzzing Uncovers Two More Vulnerabilities in wolfSSL" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-weight: bold;"&gt;Daniel Pouzzner from &lt;a href="https://www.wolfssl.com/"&gt;wolfSSL&lt;/a&gt; has challenged us to find 3 more vulnerabilities in the &lt;a href="https://github.com/wolfSSL/wolfssl"&gt;wolfSSL library&lt;/a&gt;, after we found the &lt;a href="https://www.code-intelligence.com/blog/ai-generated-fuzz-test-wolfssl-vulnerability"&gt;first one&lt;/a&gt; in October 2024. We weren't quite able to find three, but here are the additional two that we found:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;span style="font-weight: bold;"&gt;Heap buffer overflow WRITE in wolfSSL_d2i_RSAPrivateKey_bio. Fixed in &lt;/span&gt;&lt;a href="https://github.com/wolfSSL/wolfssl/pull/8426" style="font-weight: bold;"&gt;PR 8426&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="font-weight: bold;"&gt;Stack buffer overflow READ into heap buffer overflow WRITE in wolfSSL_SMIME_write_PKCS7. Fixed in &lt;/span&gt;&lt;a href="https://github.com/wolfSSL/wolfssl/pull/8466" style="font-weight: bold;"&gt;PR 8466&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;.&lt;/span&gt;&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p style="font-weight: bold;"&gt;Both vulnerabilities were fixed in wolfSSL version 5.8.0, released on 24 April 2025. The fuzz tests that found these vulnerabilities were generated by &lt;a href="https://www.code-intelligence.com/blog/meet-ai-test-agent-to-find-vulnerabilities-autonomously"&gt;our AI Test Agent&lt;/a&gt;.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.code-intelligence.com/blog/ai-automated-fuzz-test-uncovers-vulnerabilities-in-wolfssl" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.code-intelligence.com/hubfs/wolfssl%202.png" alt="AI-automated Fuzzing Uncovers Two More Vulnerabilities in wolfSSL" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-weight: bold;"&gt;Daniel Pouzzner from &lt;a href="https://www.wolfssl.com/"&gt;wolfSSL&lt;/a&gt; has challenged us to find 3 more vulnerabilities in the &lt;a href="https://github.com/wolfSSL/wolfssl"&gt;wolfSSL library&lt;/a&gt;, after we found the &lt;a href="https://www.code-intelligence.com/blog/ai-generated-fuzz-test-wolfssl-vulnerability"&gt;first one&lt;/a&gt; in October 2024. We weren't quite able to find three, but here are the additional two that we found:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;span style="font-weight: bold;"&gt;Heap buffer overflow WRITE in wolfSSL_d2i_RSAPrivateKey_bio. Fixed in &lt;/span&gt;&lt;a href="https://github.com/wolfSSL/wolfssl/pull/8426" style="font-weight: bold;"&gt;PR 8426&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="font-weight: bold;"&gt;Stack buffer overflow READ into heap buffer overflow WRITE in wolfSSL_SMIME_write_PKCS7. Fixed in &lt;/span&gt;&lt;a href="https://github.com/wolfSSL/wolfssl/pull/8466" style="font-weight: bold;"&gt;PR 8466&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;.&lt;/span&gt;&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p style="font-weight: bold;"&gt;Both vulnerabilities were fixed in wolfSSL version 5.8.0, released on 24 April 2025. The fuzz tests that found these vulnerabilities were generated by &lt;a href="https://www.code-intelligence.com/blog/meet-ai-test-agent-to-find-vulnerabilities-autonomously"&gt;our AI Test Agent&lt;/a&gt;.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=7466322&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.code-intelligence.com%2Fblog%2Fai-automated-fuzz-test-uncovers-vulnerabilities-in-wolfssl&amp;amp;bu=https%253A%252F%252Fwww.code-intelligence.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>AI</category>
      <category>Security Testing</category>
      <category>Vulnerabilities</category>
      <category>C/C++</category>
      <category>Embedded Systems</category>
      <pubDate>Wed, 11 Jun 2025 08:44:46 GMT</pubDate>
      <guid>https://www.code-intelligence.com/blog/ai-automated-fuzz-test-uncovers-vulnerabilities-in-wolfssl</guid>
      <dc:date>2025-06-11T08:44:46Z</dc:date>
      <dc:creator>Peter Samarin</dc:creator>
    </item>
    <item>
      <title>How to Get Started With Fuzz Testing</title>
      <link>https://www.code-intelligence.com/blog/how_to_get_started_with_fuzz_testing</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.code-intelligence.com/blog/how_to_get_started_with_fuzz_testing" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.code-intelligence.com/hubfs/how%20to%20get%20started%20with%20fuzzing.png" alt="How to Get Started With Fuzz Testing" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;Scope of the project&lt;/h2&gt; 
&lt;p&gt;If you recognize the benefits that fuzz testing can bring to your software security but are new to it, read on. In this blog post, you’ll learn what you need to consider &lt;em&gt;before &lt;/em&gt;implementing fuzz testing in your company to ensure a smooth and successful adoption.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.code-intelligence.com/blog/how_to_get_started_with_fuzz_testing" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.code-intelligence.com/hubfs/how%20to%20get%20started%20with%20fuzzing.png" alt="How to Get Started With Fuzz Testing" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;Scope of the project&lt;/h2&gt; 
&lt;p&gt;If you recognize the benefits that fuzz testing can bring to your software security but are new to it, read on. In this blog post, you’ll learn what you need to consider &lt;em&gt;before &lt;/em&gt;implementing fuzz testing in your company to ensure a smooth and successful adoption.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=7466322&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.code-intelligence.com%2Fblog%2Fhow_to_get_started_with_fuzz_testing&amp;amp;bu=https%253A%252F%252Fwww.code-intelligence.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Security Testing</category>
      <category>C/C++</category>
      <category>Automotive</category>
      <pubDate>Wed, 28 May 2025 12:35:14 GMT</pubDate>
      <guid>https://www.code-intelligence.com/blog/how_to_get_started_with_fuzz_testing</guid>
      <dc:date>2025-05-28T12:35:14Z</dc:date>
      <dc:creator>Natalia Kazankova</dc:creator>
    </item>
    <item>
      <title>Automotive Supplier Finds 32% of Bugs Through Fuzz Testing</title>
      <link>https://www.code-intelligence.com/blog/automotive_suppplier_finds_third_of_bugs_through_fuzz_testing</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.code-intelligence.com/blog/automotive_suppplier_finds_third_of_bugs_through_fuzz_testing" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.code-intelligence.com/hubfs/Screenshot%20at%20Apr%2023%2010-26-59.png" alt="iso-21434-cals" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;Scope of the project&lt;/h2&gt; 
&lt;p&gt;An automotive supplier employs static analysis and Code Intelligence's &lt;a href="https://www.code-intelligence.com/product-ci-fuzz"&gt;Fuzz Testing&lt;/a&gt; to assess software within a separate business unit. The project comprises 10 million lines of C code, adhering to Classic AUTOSAR standards.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.code-intelligence.com/blog/automotive_suppplier_finds_third_of_bugs_through_fuzz_testing" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.code-intelligence.com/hubfs/Screenshot%20at%20Apr%2023%2010-26-59.png" alt="iso-21434-cals" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;Scope of the project&lt;/h2&gt; 
&lt;p&gt;An automotive supplier employs static analysis and Code Intelligence's &lt;a href="https://www.code-intelligence.com/product-ci-fuzz"&gt;Fuzz Testing&lt;/a&gt; to assess software within a separate business unit. The project comprises 10 million lines of C code, adhering to Classic AUTOSAR standards.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=7466322&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.code-intelligence.com%2Fblog%2Fautomotive_suppplier_finds_third_of_bugs_through_fuzz_testing&amp;amp;bu=https%253A%252F%252Fwww.code-intelligence.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>C/C++</category>
      <category>Automotive</category>
      <pubDate>Wed, 23 Apr 2025 08:43:27 GMT</pubDate>
      <guid>https://www.code-intelligence.com/blog/automotive_suppplier_finds_third_of_bugs_through_fuzz_testing</guid>
      <dc:date>2025-04-23T08:43:27Z</dc:date>
      <dc:creator>Natalia Kazankova</dc:creator>
    </item>
    <item>
      <title>Memory Safety Bugs: An In-Depth Look At Critical Issues | Blog</title>
      <link>https://www.code-intelligence.com/blog/memory_safety_corruption</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.code-intelligence.com/blog/memory_safety_corruption" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.code-intelligence.com/hubfs/image%20memory%20safety.png" alt="Memory Safety Bugs: An In-Depth Look At Critical Issues | Blog" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Memory safety vulnerabilities remain among the most widespread and exploited security issues. They occur in C and C++ projects, which are widely used across embedded systems, including &lt;a href="https://www.code-intelligence.com/industry/automotive"&gt;automotive&lt;/a&gt;, &lt;a href="https://www.code-intelligence.com/industry/medical-devices-security"&gt;medical devices&lt;/a&gt;, and avionics. Read on to learn why they can happen and how to prevent them.&lt;/p&gt; 
&lt;h4 style="font-weight: bold; text-align: left;"&gt;Content&lt;/h4&gt; 
&lt;ul&gt; 
 &lt;ul&gt; 
  &lt;li&gt;What Are Memory Safety Issues&lt;/li&gt; 
  &lt;li&gt;Why Memory Safety Matters&lt;/li&gt; 
  &lt;li&gt;Real-World Examples of Memory Corruption&lt;/li&gt; 
  &lt;li&gt;Example of a Memory Safety Bug&lt;/li&gt; 
  &lt;li&gt;How to Detect Memory Corruption&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/ul&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.code-intelligence.com/blog/memory_safety_corruption" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.code-intelligence.com/hubfs/image%20memory%20safety.png" alt="Memory Safety Bugs: An In-Depth Look At Critical Issues | Blog" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Memory safety vulnerabilities remain among the most widespread and exploited security issues. They occur in C and C++ projects, which are widely used across embedded systems, including &lt;a href="https://www.code-intelligence.com/industry/automotive"&gt;automotive&lt;/a&gt;, &lt;a href="https://www.code-intelligence.com/industry/medical-devices-security"&gt;medical devices&lt;/a&gt;, and avionics. Read on to learn why they can happen and how to prevent them.&lt;/p&gt; 
&lt;h4 style="font-weight: bold; text-align: left;"&gt;Content&lt;/h4&gt; 
&lt;ul&gt; 
 &lt;ul&gt; 
  &lt;li&gt;What Are Memory Safety Issues&lt;/li&gt; 
  &lt;li&gt;Why Memory Safety Matters&lt;/li&gt; 
  &lt;li&gt;Real-World Examples of Memory Corruption&lt;/li&gt; 
  &lt;li&gt;Example of a Memory Safety Bug&lt;/li&gt; 
  &lt;li&gt;How to Detect Memory Corruption&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/ul&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=7466322&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.code-intelligence.com%2Fblog%2Fmemory_safety_corruption&amp;amp;bu=https%253A%252F%252Fwww.code-intelligence.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Security Testing</category>
      <category>Vulnerabilities</category>
      <category>C/C++</category>
      <category>Embedded Systems</category>
      <pubDate>Wed, 16 Apr 2025 14:13:48 GMT</pubDate>
      <guid>https://www.code-intelligence.com/blog/memory_safety_corruption</guid>
      <dc:date>2025-04-16T14:13:48Z</dc:date>
      <dc:creator>Natalia Kazankova</dc:creator>
    </item>
    <item>
      <title>Medical Device Regulation (MDR): Why Cybersecurity And Fuzz Testing Are No Longer Optional</title>
      <link>https://www.code-intelligence.com/blog/medical_device_regulation_mdr_and_fuzzing</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.code-intelligence.com/blog/medical_device_regulation_mdr_and_fuzzing" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.code-intelligence.com/hubfs/MDR%20regulation%20blog%20post.png" alt="Medical Device Regulation (MDR): Why Cybersecurity And Fuzz Testing Are No Longer Optional" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;ul&gt; 
 &lt;li&gt;Europe has shifted from the old MDD (Medical Device Directive) to the newer MDR (Medical Device Regulation).&lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;The transition has caused &lt;span&gt;&lt;strong&gt;confusion and inconsistency&lt;/strong&gt;&lt;/span&gt;, as some devices are still MDD-certified and need to transition, while others are already under MDR.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;MDR &lt;span&gt;&lt;strong&gt;specifies “what” needs to be done&lt;/strong&gt;&lt;/span&gt;, but not “how” to do it — leaving gaps in implementation details.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Fuzz testing &lt;/span&gt;is explicitly mentioned in the MDCG guidance documents (MDCG 2019-16) and IEC 81001-5-1. Both documents are considered state of the art. They are not legally binding but auditors may treat them mandatory.&amp;nbsp;&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.code-intelligence.com/blog/medical_device_regulation_mdr_and_fuzzing" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.code-intelligence.com/hubfs/MDR%20regulation%20blog%20post.png" alt="Medical Device Regulation (MDR): Why Cybersecurity And Fuzz Testing Are No Longer Optional" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;ul&gt; 
 &lt;li&gt;Europe has shifted from the old MDD (Medical Device Directive) to the newer MDR (Medical Device Regulation).&lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;The transition has caused &lt;span&gt;&lt;strong&gt;confusion and inconsistency&lt;/strong&gt;&lt;/span&gt;, as some devices are still MDD-certified and need to transition, while others are already under MDR.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;MDR &lt;span&gt;&lt;strong&gt;specifies “what” needs to be done&lt;/strong&gt;&lt;/span&gt;, but not “how” to do it — leaving gaps in implementation details.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Fuzz testing &lt;/span&gt;is explicitly mentioned in the MDCG guidance documents (MDCG 2019-16) and IEC 81001-5-1. Both documents are considered state of the art. They are not legally binding but auditors may treat them mandatory.&amp;nbsp;&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=7466322&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.code-intelligence.com%2Fblog%2Fmedical_device_regulation_mdr_and_fuzzing&amp;amp;bu=https%253A%252F%252Fwww.code-intelligence.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>C/C++</category>
      <category>Medical Devices</category>
      <pubDate>Tue, 08 Apr 2025 14:29:19 GMT</pubDate>
      <guid>https://www.code-intelligence.com/blog/medical_device_regulation_mdr_and_fuzzing</guid>
      <dc:date>2025-04-08T14:29:19Z</dc:date>
      <dc:creator>Natalia Kazankova</dc:creator>
    </item>
    <item>
      <title>AI-automated Fuzzing Found a Dynamic Stack Buffer Overflow in abseil-cpp</title>
      <link>https://www.code-intelligence.com/blog/cifuzz-found-vulnerability-in-abseil-cpp</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.code-intelligence.com/blog/cifuzz-found-vulnerability-in-abseil-cpp" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.code-intelligence.com/hubfs/Vulnerability%20in%20abseil.png" alt="abseil-cpp" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-weight: bold;"&gt;A dynamic stack buffer overflow vulnerability in the Abseil C++ library (abseil-cpp) was autonomously identified through AI-enhanced fuzz testing using &lt;a href="https://www.code-intelligence.com/product-ci-fuzz"&gt;CI Fuzz&lt;/a&gt;’s AI Test Agent and has been fully addressed with &lt;a href="https://github.com/abseil/abseil-cpp/commit/fd86aa79dd521bf0e375a806d6eb410df8051c8c"&gt;a patch&lt;/a&gt;. This post dives into the vulnerability, its discovery, and its implications for systems relying on this widely-used library.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.code-intelligence.com/blog/cifuzz-found-vulnerability-in-abseil-cpp" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.code-intelligence.com/hubfs/Vulnerability%20in%20abseil.png" alt="abseil-cpp" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-weight: bold;"&gt;A dynamic stack buffer overflow vulnerability in the Abseil C++ library (abseil-cpp) was autonomously identified through AI-enhanced fuzz testing using &lt;a href="https://www.code-intelligence.com/product-ci-fuzz"&gt;CI Fuzz&lt;/a&gt;’s AI Test Agent and has been fully addressed with &lt;a href="https://github.com/abseil/abseil-cpp/commit/fd86aa79dd521bf0e375a806d6eb410df8051c8c"&gt;a patch&lt;/a&gt;. This post dives into the vulnerability, its discovery, and its implications for systems relying on this widely-used library.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=7466322&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.code-intelligence.com%2Fblog%2Fcifuzz-found-vulnerability-in-abseil-cpp&amp;amp;bu=https%253A%252F%252Fwww.code-intelligence.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>News &amp; Events</category>
      <category>AI</category>
      <category>Security Testing</category>
      <category>Vulnerabilities</category>
      <category>C/C++</category>
      <pubDate>Fri, 07 Mar 2025 10:13:05 GMT</pubDate>
      <author>info@code-intelligence.com (Markus Zoppelt)</author>
      <guid>https://www.code-intelligence.com/blog/cifuzz-found-vulnerability-in-abseil-cpp</guid>
      <dc:date>2025-03-07T10:13:05Z</dc:date>
    </item>
    <item>
      <title>AI-Automated Fuzzing Found a Heap Buffer Overflow in AWS C Common Library</title>
      <link>https://www.code-intelligence.com/blog/cifuzz-found-vulnerability-in-aws-c-common</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.code-intelligence.com/blog/cifuzz-found-vulnerability-in-aws-c-common" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.code-intelligence.com/hubfs/AWS%20vulnerability.png" alt="AI-Automated Fuzzing Found a Heap Buffer Overflow in AWS C Common Library" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-weight: bold;"&gt;A critical heap buffer overflow vulnerability in the AWS C Common library was discovered autonomously through an AI-automated fuzz testing solution, &lt;a href="https://www.code-intelligence.com/product-ci-fuzz"&gt;CI Fuzz&lt;/a&gt;, and has been fully addressed with &lt;a href="https://github.com/awslabs/aws-c-common/pull/1185"&gt;a patch&lt;/a&gt;. In this post, we explore the vulnerability and its potential impact on embedded systems.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.code-intelligence.com/blog/cifuzz-found-vulnerability-in-aws-c-common" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.code-intelligence.com/hubfs/AWS%20vulnerability.png" alt="AI-Automated Fuzzing Found a Heap Buffer Overflow in AWS C Common Library" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-weight: bold;"&gt;A critical heap buffer overflow vulnerability in the AWS C Common library was discovered autonomously through an AI-automated fuzz testing solution, &lt;a href="https://www.code-intelligence.com/product-ci-fuzz"&gt;CI Fuzz&lt;/a&gt;, and has been fully addressed with &lt;a href="https://github.com/awslabs/aws-c-common/pull/1185"&gt;a patch&lt;/a&gt;. In this post, we explore the vulnerability and its potential impact on embedded systems.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=7466322&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.code-intelligence.com%2Fblog%2Fcifuzz-found-vulnerability-in-aws-c-common&amp;amp;bu=https%253A%252F%252Fwww.code-intelligence.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>News &amp; Events</category>
      <category>AI</category>
      <category>Security Testing</category>
      <category>Vulnerabilities</category>
      <category>C/C++</category>
      <pubDate>Wed, 26 Feb 2025 12:57:48 GMT</pubDate>
      <author>info@code-intelligence.com (Markus Zoppelt)</author>
      <guid>https://www.code-intelligence.com/blog/cifuzz-found-vulnerability-in-aws-c-common</guid>
      <dc:date>2025-02-26T12:57:48Z</dc:date>
    </item>
    <item>
      <title>Top Six Most Dangerous Vulnerabilities in C and C++</title>
      <link>https://www.code-intelligence.com/blog/most-dangerous-vulnerabilities-cwes-in-c-2025</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.code-intelligence.com/blog/most-dangerous-vulnerabilities-cwes-in-c-2025" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.code-intelligence.com/hubfs/Blog%20the%206%20most%20vulnerab%20in%20c.png" alt="Top Six Most Dangerous Vulnerabilities in C and C++" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-weight: bold;"&gt;C and C++ programming are notorious for being bug-prone. Let’s look at the most dangerous software weaknesses in 2024 that are relevant for C and C++, so that you know what type of issues to test your code against in 2025.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.code-intelligence.com/blog/most-dangerous-vulnerabilities-cwes-in-c-2025" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.code-intelligence.com/hubfs/Blog%20the%206%20most%20vulnerab%20in%20c.png" alt="Top Six Most Dangerous Vulnerabilities in C and C++" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-weight: bold;"&gt;C and C++ programming are notorious for being bug-prone. Let’s look at the most dangerous software weaknesses in 2024 that are relevant for C and C++, so that you know what type of issues to test your code against in 2025.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=7466322&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.code-intelligence.com%2Fblog%2Fmost-dangerous-vulnerabilities-cwes-in-c-2025&amp;amp;bu=https%253A%252F%252Fwww.code-intelligence.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Vulnerabilities</category>
      <category>C/C++</category>
      <pubDate>Fri, 14 Feb 2025 14:05:00 GMT</pubDate>
      <guid>https://www.code-intelligence.com/blog/most-dangerous-vulnerabilities-cwes-in-c-2025</guid>
      <dc:date>2025-02-14T14:05:00Z</dc:date>
      <dc:creator>Natalia Kazankova</dc:creator>
    </item>
    <item>
      <title>Meet Spark, an AI Test Agent That Autonomously Uncovers Vulnerabilities</title>
      <link>https://www.code-intelligence.com/blog/meet-ai-test-agent-to-find-vulnerabilities-autonomously</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.code-intelligence.com/blog/meet-ai-test-agent-to-find-vulnerabilities-autonomously" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.code-intelligence.com/hubfs/Frame%204.png" alt="Meet Spark, an AI Test Agent That Autonomously Uncovers Vulnerabilities" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;span style="font-size: 18px; color: #0e0e0e;"&gt;We’re thrilled to announce the general availability of Spark, an AI Test Agent that lowers the entry barrier to white-box fuzz testing. In this blog, we explain how Spark works and share the main results from its beta testing that prove its effectiveness.&lt;/span&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.code-intelligence.com/blog/meet-ai-test-agent-to-find-vulnerabilities-autonomously" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.code-intelligence.com/hubfs/Frame%204.png" alt="Meet Spark, an AI Test Agent That Autonomously Uncovers Vulnerabilities" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;span style="font-size: 18px; color: #0e0e0e;"&gt;We’re thrilled to announce the general availability of Spark, an AI Test Agent that lowers the entry barrier to white-box fuzz testing. In this blog, we explain how Spark works and share the main results from its beta testing that prove its effectiveness.&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=7466322&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.code-intelligence.com%2Fblog%2Fmeet-ai-test-agent-to-find-vulnerabilities-autonomously&amp;amp;bu=https%253A%252F%252Fwww.code-intelligence.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>News &amp; Events</category>
      <category>AI</category>
      <category>Security Testing</category>
      <category>C/C++</category>
      <pubDate>Wed, 29 Jan 2025 18:51:58 GMT</pubDate>
      <guid>https://www.code-intelligence.com/blog/meet-ai-test-agent-to-find-vulnerabilities-autonomously</guid>
      <dc:date>2025-01-29T18:51:58Z</dc:date>
      <dc:creator>Natalia Kazankova</dc:creator>
    </item>
    <item>
      <title>Top Fuzz Testing Tools of 2025: Feature Comparison</title>
      <link>https://www.code-intelligence.com/blog/top-fuzz-testing-tools</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.code-intelligence.com/blog/top-fuzz-testing-tools" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.code-intelligence.com/hubfs/Top%20Fuzzing%20Tools%202025.png" alt="Top Fuzz Testing Tools of 2025: Feature Comparison" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;In 2025, fuzz testing has become an essential practice for ensuring software security and reliability. By identifying vulnerabilities through randomized input testing, fuzzing helps development teams uncover bugs that traditional testing methods—such as static analysis and penetration testing—often miss. With rapid advancements in security tools, let’s explore the top fuzz testing tools of 2025, their key features, benefits, and how they compare.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.code-intelligence.com/blog/top-fuzz-testing-tools" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.code-intelligence.com/hubfs/Top%20Fuzzing%20Tools%202025.png" alt="Top Fuzz Testing Tools of 2025: Feature Comparison" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;In 2025, fuzz testing has become an essential practice for ensuring software security and reliability. By identifying vulnerabilities through randomized input testing, fuzzing helps development teams uncover bugs that traditional testing methods—such as static analysis and penetration testing—often miss. With rapid advancements in security tools, let’s explore the top fuzz testing tools of 2025, their key features, benefits, and how they compare.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=7466322&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.code-intelligence.com%2Fblog%2Ftop-fuzz-testing-tools&amp;amp;bu=https%253A%252F%252Fwww.code-intelligence.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Security Testing</category>
      <pubDate>Wed, 29 Jan 2025 18:30:32 GMT</pubDate>
      <guid>https://www.code-intelligence.com/blog/top-fuzz-testing-tools</guid>
      <dc:date>2025-01-29T18:30:32Z</dc:date>
      <dc:creator>Natalia Kazankova</dc:creator>
    </item>
  </channel>
</rss>
