Log inSign up
Trail of Bits
4,350 posts
Trail of Bits profile banner
@trailofbits

Trail of Bits

@trailofbits
We help secure the world’s most targeted organizations and products. We combine security research with an attacker mentality to reduce risk and fortify code.
New York, NY
trailofbits.com
Joined March 2010
261
Following
39.1K
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • Pinned
    @trailofbits
    Trail of Bits
    @trailofbits
    Aug 31
    We launched as a trusted auditor for Signal's Automatic Key Verification, watched GPT 5.6-Cyber chain three 0-days into a VM escape, and found a Provenance bug representing ~$500K in drainable HASH. Plus 8 new public reviews, 2 open-source tools, and more. August Tribune:
    Image
    8
  • @trailofbits
    Trail of Bits
    @trailofbits
    Sep 4
    aiohttp is downloaded 600M+ times a month. Its maintainers just recapped a year of security work, including the 10 issues (8 CVEs) we reported through Patch the Planet. Every fix shipped days later in 3.14.1. aio-libs.org/news/2026/secu…
    2
  • @trailofbits
    Trail of Bits
    @trailofbits
    Sep 3
    1,535 potential bugs found, 1,017 awaiting patches, 326 fixes open upstream, 192 merged. Since Aug 4: +398 bugs, +46 merged, 55 codebases under review, and scapy has overtaken vllm as the most-reported codebase in Patch the Planet.
    Image
    Dashboard · Patch the Planet · Trail of Bits
    From trailofbits.com
  • @trailofbits
    Trail of Bits
    @trailofbits
    Aug 27
    We signed the call for collective action. Across 3 months, we audited 50 open-source projects using frontier cyber models. To date, we've found 1,268 potential issues and wrote 298 patches. Critical infrastructure around the world carries the same technical debt, but has far
    @gdb
    Greg Brockman
    OpenAI
    @gdb
    Aug 27
    An open letter for a global surge in cyber defense, signed by over 100 organizations including Anthropic, AWS, Google, Microsoft, OpenAI, and Oracle.
    Article cover image
    Article
    A call for collective action on cyber defense
    An open letter for a global surge in cyber defense, signed by over 100 organizations including Anthropic, AWS, Google, Microsoft, OpenAI, and Oracle. We have a limited window to strengthen cyber...
    13
  • @trailofbits
    Trail of Bits
    @trailofbits
    Aug 26
    We asked GPT 5.6-Cyber to escape a VM used to sandbox agents. It broke out three times. In its final escape, the agent found three 0-days on its own and chained them into a working exploit.
    Image
    VMs won't contain cyber-capable agents
    From blog.trailofbits.com
    65
Advertisement
Advertisement