cd /news/ai-safety/back-to-the-fuzzer-the-future-of-vul… · home › topics › ai-safety › article
[ARTICLE · art-147712] src=brightsec.com ↗ pub= topic=ai-safety verified=true sentiment=↑ positive

Back to the Fuzzer: The Future of Vulnerability Discovery Was Built in 2018

Bright reintroduced its STAR Fuzzer, an AI-guided structural fuzzer originally released in 2018 as NeuraLegion's NexPloit, after running it for two days in an automated pipeline against multiple open-source libraries and applications. The company reported that 45% of the tested projects had High or Critical issues spanning memory corruption, denial of service, path traversal and escapes, and that 37% of the vulnerable projects appear on Google's OSS-fuzz list. Bright said the new version pairs the fuzzer with its STAR agentic harness to automate root cause analysis, harness creation and runtime, removing the manual work that stalled the original product in the pre-LLM era.

read6 min views5 publishedOct 8, 2026
Back to the Fuzzer: The Future of Vulnerability Discovery Was Built in 2018
Image: Brightsec (auto-discovered)

Marc Andressen is famously quoted saying that “being too early is the primary reason why qualified startups fail, not being too late”. This was almost the case for bright 8 years ago, but we were able to pivot and build a real business providing value for many customers. Now, technology has caught up to our original vision and we are reintroducing the Bright STAR Fuzzer.

In 2018 after around a year of covert research on bio-mimicry and evolutionary behavior Bright (at that time NeuraLegion), released our product, an AI guided fuzzer way before AI was cool. This was before LLMs were a thing, and was around the time neural networks became a new fashion for visual analysis and text\speech recognition.

In our research we proved something interesting, security issues and bugs can be converged into, not discovered by accident, and behavior of a system can slowly degrade leading into a fault. Armed with this new understanding we created a generic structural fuzzer that needs no dictionary and uses an advanced evolutionary algorithm to converge into the most complex and hard to uncover issues.

The solution was live, we generated significant interest and won 1st place as The Most Interesting Technology in Israel’s CyberTech 2019 conference (“Winners of CyberTech competition as most innovative and disruptive solution, NexPloit is the world’s first AI-powered Application Security Testing solution”).

The only problem was, the world was not yet ready.

ConductingAnalyzing root cause analysis in a pre-LLM world meant digging into code that sometimes was a 3rd party library, it meant manually writing the harness by hand and deciding on what levers to pulluse.

We decided to pivot But not only due to the technical complications, but also because changed our course, it was also the superb success of the tool, generating causing interest from security agencies and offensive security firms while we wanted to provide solutions tokeep in the civilian enterprise market. SAnd so, we heard from listened to our customers and slowly shifted to Dev Centric DAST.

The world finally caughttching up

2026 is nearing itsat its end, and with it, the ability to automate root cause analysis, deepanalysis deep dives, harness creation and runtime, and application containment on the fly has becaome a reality, and not just a reality, one that can actually scale up across an organization’s codebase.

With thoese new realities we decided to revisitlooked back at our core technology and with careful consideration for the power and capabilities of what we built we created an automated harness around the algorithm and code, combining our fuzzer with Bright’s STAR agentic harness.

Developers Nno morelonger would developers need to manually dig into root cause, they woulddo not need to write their own fixes or understand complex low level handling, the pure power of Bright’s fuzzer just became a single click autonomous solution.

But before we could share it with the worldgive it away, we hadneeded to test it ourselves and prove that it works, and so we did.

Welcome to the ZeroDay Factory

We started by took two days to runningrun the solution on multiple opensource solutions in an automated pipeline we created for two days. This included various , from libraries to& applications, from web based technologies to low level binary parsers.

But as our CEO likes to say, talk is cheapwords are words show me theand numbers are numbers, so let’s back up our claims:

Out of the projects we tested 45% had High or Critical issues, those span different vulnerability families from memory corruptions (read and write) to denial of service (memory bombs and process death) and others vulnerabilities includinglike path traversal and escapes.

37% of the vulnerable projects are in gGoogle’s own OSS-fuzz list, which means a decade of constant fuzzing and issue hunting still proves a viable “hunting” finding grounds for the Brightour own fuzzer. Shameless plug (let’s be honest, if you are still reading you are a geek like me and want to know about this) Stay tuned for my upcoming post next week in which I will dive into how the Bright fuzzer is different and why it finds things other fuzzers can’t find.

We already have a number of Ppublished advisories are already available for those who are interested at:

  1. TwelveMonkeys DDS OutOfMemoryError (38-byte file forces a multi-GB allocation) – GHSA-fwp7-38wp-mmxw , published, fixed in 3.15.0
  2. Fider image decompression-bomb OOM (436 KB PNG expands to about 562 MB) – GHSA-7cw3-7xh9-529r , published, fixed in 0.38.0

A few have been opened as public issues due to no disclosure policy:

1. htop out-of-bounds read in the /proc/PID/stat parser – [htop-dev/htop#2101](https://github.com/htop-dev/htop/issues/2101) , fixed
2. universal-ctags null-pointer access in foreachEntriesInScope – [universal-ctags/ctags#4497](https://github.com/universal-ctags/ctags/issues/4497) , fixed
3. scrimage GIF decompression bomb (35-byte GIF forces a multi-GB OOM) – [sksamuel/scrimage#893](https://github.com/sksamuel/scrimage/issues/893) , fixed in 4.6.8

Most of the issues the fuzzer found are still undisclosed and will be shared and published when fixes will be published.

Numbers are great, but let’s for a second But aside from the pure numbers, let’s dig into the talk about Fider finding.

Fider has been the battle ground for AI PT companies showing their skills. worth, aA recent article from Doyensec compared XBOW v.s Aikido against the Fider app, each found its own share of issues and ran for hours and even days against the target using smart LLMs to find and detect all kind of vulnerabilities both from the web side and by code analysis.

After all theseof those findings Doyensec contacted Fider and reported the issues which were all fixed, a few more companies then followed suit which brought even more issues to be disclosed and fixed as well.

We took the latest version, the one whoich was battle tested against multiple companies using advanced LLMs and AI products and gave our fuzzer a run. It took around 12 minutes for it to find a 0day in the imaging processing logic which allows a tiny few bytes image to overload the server memory with GBs of allocations and take down a whole instance.

And tThis, is the biggest point, while LLM based Pentesting solutionsother hunts for the mundane and expected, our fuzzer hunts for the unexpected and hard to find vulnerabilities, because in the new age of LLMs in which where Pentesting has becaome a commodity, and AI can easily find vulnerabilities with a simple prompt, the unexpected which the AI fails to identify and detect becomes the new frontier of security research and testing.

To add a bit more here, the Bright fuzzer is conceptually an AFL fuzzer with many additional capabilities. It systematically generates inputs and executes software to discover crashes and other observable failures. In comparison, LLM based solutions like Codex, Claude and others can understand code, reason about potential vulnerabilities, write tests, execute tools and attempt to exploit weaknesses. These are very different capabilities that find different vulnerabilities.

Better Together, With STAR

Bright’s STAR provides an autonomous harness for vulnerability detection, remediation and validation, all in one flow. And this is where the fuzzer fits perfectly.

The new fuzzing mode in STAR uses Bright’s fuzzer to uncoverdetect deep and complex issues easily, detect and identify the root cause, fix the issues, then validate they are indeed fixed using the fuzzer replay functionality.

It can also validate SAST findings by live fuzzing of functions and parts of the target in the harness, ensuring real behavior handling and security issue focus instead of just noise and false positivesFP from SAST analysis.

  • Fider findings – PR view, full details showing the exploitation impact and payloads. We will start sharing all the Bright fuzzer findings on a regular basis so follow Bright on all social channels to ongoing updates and stay tuned for my post next week.
── more in #ai-safety 4 stories · sorted by recency
── more on @bright 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/back-to-the-fuzzer-t…] indexed:0 read:6min 2026-10-08 · —