Trailmark turns code into graphs
We’re open-sourcing Trailmark, a library that parses source code into a queryable call graph of functions, classes, call relationships, and semantic metadata, then exposes that graph through a P
We’re open-sourcing Trailmark, a library that parses source code into a queryable call graph of functions, classes, call relationships, and semantic metadata, then exposes that graph through a P
Two weeks ago, Google’s Quantum AI group published a zero-knowledge proof of a quantum circuit so optimized, they concluded that first-generation quantum computers will break elliptic curve cryptograp
We added a new chapter to our Testing Handbook: a comprehensive security checklist for C and C++ code. We’ve identified a broad range of common bug classes, known footguns, and API gotchas across C an
This post is adapted from a talk I gave at [un]prompted, the AI security practitioner conference. Thanks to Gadi Evron for inviting me to speak. You can watch the recorded presentation below or downlo
Using dimensional analysis, you can categorically rule out a whole category of logic and arithmetic bugs that plague DeFi formulas. No code changes required, just better reasoning! One of the first le
Before launching their Comet browser, Perplexity hired us to test the security of their AI-powered browsing features. Using adversarial testing guided by our TRAIL threat model, we demonstrated how fo
Two popular AES libraries, aes-js and pyaes, “helpfully” provide a default IV in their AES-CTR API, leading to a large number of key/IV reuse bugs. These bugs potentially affect thousands of downstrea
Last year, our engineers submitted over 375 pull requests that were merged into non–Trail of Bits repositories, touching more than 90 projects from cryptography libraries to the Rust compiler. This wo
Software signatures carry an invisible expiration date. The container image or firmware you sign today might be deployed for 20 years, but the cryptographic signature protecting it may become untrustw
Explore the military and terrorist groups collaborating with Hamas in the Israel-Hamas War, based on reports and open-source intelligence The post Beyond Hamas: Militant and Terrorist Groups Involved
Analyzing Telegram's role in facilitating communication and strategy for Hamas and PIJ during the initial days of the Israel-Hamas War. The post The First 72 Hours of the Israel-Hamas War: Hamas and P
Flashpoint has earned multiple trust badges from G2's Fall 2023 Reports, affirming our unwavering commitment to delivering timely, contextual intelligence to our clients. The post G2 Recognizes Flashp
We sit down for a Q&A with Michael Raypold to discuss the launch of the Flashpoint Firehose, our new data-as-a-service solution The post The Flashpoint Firehose: 5 Questions With Michael Raypold,