# Back to the Fuzzer: The Future of Vulnerability Discovery Was Built in 2018

> Source: <https://brightsec.com/blog/back-to-the-fuzzer-the-future-of-vulnerability-discovery-was-built-in-2018/>
> Published: 2026-10-08 16:57:26+00:00

**Marc Andressen is famously quoted saying that “being too early is the primary reason why qualified startups fail, not being too late”.** This was almost the case for bright 8 years ago, but we were able to pivot and build a real business providing value for many customers. Now, technology has caught up to our original vision and we are reintroducing the Bright STAR Fuzzer. 

In 2018 after around a year of covert research on bio-mimicry and evolutionary behavior Bright (at that time NeuraLegion), released our product, an AI guided fuzzer way before AI was cool. This was before LLMs were a thing, and was around the time neural networks became a new fashion for visual analysis and text\speech recognition.

In our research we proved something interesting, security issues and bugs can be converged into, not discovered by accident, and behavior of a system can slowly degrade leading into a fault. Armed with this new understanding we created a generic structural fuzzer that needs no dictionary and uses an advanced evolutionary algorithm to converge into the most complex and hard to uncover issues.

The solution was live, we generated significant interest and won 1st place as ***The Most Interesting Technology*** in Israel’s CyberTech 2019 conference (“Winners of CyberTech competition as most innovative and disruptive solution, NexPloit is the world’s first AI-powered Application Security Testing solution”).

The only problem was, the world was not yet ready.

ConductingAnalyzing root cause analysis in a pre-LLM world meant digging into code that sometimes was a 3rd party library, it meant manually writing the harness by hand and deciding on what levers to pulluse.

We decided to pivot But not only due to the technical complications, but also because changed our course, it was also the superb success of the tool, generating causing interest from security agencies and offensive security firms while we wanted to provide solutions tokeep in the civilian enterprise market. SAnd so, we heard from listened to our customers and slowly shifted to Dev Centric DAST.

**The world finally caughttching up**

2026 is nearing itsat its end, and with it, the ability to automate root cause analysis, deepanalysis deep dives, harness creation and runtime, and application containment on the fly has becaome a reality, and not just a reality, one that can actually scale up across an organization’s codebase.

With thoese new realities we decided to revisitlooked back at our core technology and with careful consideration for the power and capabilities of what we built we created an automated harness around the algorithm and code, combining our fuzzer with Bright’s STAR agentic harness.

Developers Nno morelonger would developers need to manually dig into root cause, they woulddo not need to write their own fixes or understand complex low level handling, the pure power of Bright’s fuzzer just became a single click autonomous solution.

But before we could share it with the worldgive it away, we hadneeded to test it ourselves and prove that it works, and so we did.

**Welcome to the ZeroDay Factory**

We started by took two days to runningrun the solution on multiple opensource solutions in an automated pipeline we created for two days. This included various , from libraries to& applications, from web based technologies to low level binary parsers.

But as our CEO likes to say, talk is cheapwords are words show me theand numbers are numbers, so let’s back up our claims:

Out of the projects we tested 45% had High or Critical issues, those span different vulnerability families from memory corruptions (read and write) to denial of service (memory bombs and process death) and others vulnerabilities includinglike path traversal and escapes.

37% of the vulnerable projects are in gGoogle’s own OSS-fuzz list, which means a decade of constant fuzzing and issue hunting still proves a viable “hunting” finding grounds for the Brightour own fuzzer. *Shameless plug (let’s be honest, if you are still reading you are a geek like me and want to know about this) Stay tuned for my upcoming post next week in which I will dive into how the Bright fuzzer is different and why it finds things other fuzzers can’t find.*

We already have a number of Ppublished advisories are already available for those who are interested at:

1. TwelveMonkeys DDS OutOfMemoryError (38-byte file forces a multi-GB allocation) – [GHSA-fwp7-38wp-mmxw](https://github.com/haraldk/TwelveMonkeys/security/advisories/GHSA-fwp7-38wp-mmxw) , published, fixed in 3.15.0
2. Fider image decompression-bomb OOM (436 KB PNG expands to about 562 MB) – [GHSA-7cw3-7xh9-529r](https://github.com/getfider/fider/security/advisories/GHSA-7cw3-7xh9-529r) , published, fixed in 0.38.0

A few have been opened as public issues due to no disclosure policy:

1. htop out-of-bounds read in the /proc/PID/stat parser – [htop-dev/htop#2101](https://github.com/htop-dev/htop/issues/2101) , fixed
2. universal-ctags null-pointer access in foreachEntriesInScope – [universal-ctags/ctags#4497](https://github.com/universal-ctags/ctags/issues/4497) , fixed
3. scrimage GIF decompression bomb (35-byte GIF forces a multi-GB OOM) – [sksamuel/scrimage#893](https://github.com/sksamuel/scrimage/issues/893) , fixed in 4.6.8

Most of the issues the fuzzer found are still undisclosed and will be shared and published when fixes will be published.

Numbers are great, but let’s for a second But aside from the pure numbers, let’s dig into the talk about Fider finding.

**Fider** has been the battle ground for AI PT companies showing their skills. worth, aA recent article from [Doyensec compared XBOW v.s Aikido against the Fider app](https://blog.doyensec.com/2026/05/27/aikido-xbow.html), each found its own share of issues and ran for hours and even days against the target using smart LLMs to find and detect all kind of vulnerabilities both from the web side and by code analysis.

After all theseof those findings Doyensec contacted Fider and reported the issues which were all fixed, a few more companies then followed suit which brought even more issues to be disclosed and fixed as well.

We took the latest version, the one whoich was battle tested against multiple companies using advanced LLMs and AI products and gave our fuzzer a run. It took around 12 minutes for it to find a 0day in the imaging processing logic which allows a tiny few bytes image to overload the server memory with GBs of allocations and take down a whole instance.

And tThis, is the biggest point, while LLM based Pentesting solutionsother hunts for the mundane and expected, our fuzzer hunts for the unexpected and hard to find vulnerabilities, because in the new age of LLMs in which where Pentesting has becaome a commodity, and AI can easily find vulnerabilities with a simple prompt, the unexpected which the AI fails to identify and detect becomes the new frontier of security research and testing.

To add a bit more here, the Bright fuzzer is conceptually an AFL fuzzer with many additional capabilities. It systematically generates inputs and executes software to discover crashes and other observable failures. In comparison, LLM based solutions like Codex, Claude and others can understand code, reason about potential vulnerabilities, write tests, execute tools and attempt to exploit weaknesses. These are very different capabilities that find different vulnerabilities.

**Better Together, With STAR**

Bright’s STAR provides an autonomous harness for vulnerability detection, remediation and validation, all in one flow. And this is where the fuzzer fits perfectly.

The new fuzzing mode in STAR uses Bright’s fuzzer to uncoverdetect deep and complex issues easily, detect and identify the root cause, fix the issues, then validate they are indeed fixed using the fuzzer replay functionality.

It can also validate SAST findings by live fuzzing of functions and parts of the target in the harness, ensuring real behavior handling and security issue focus instead of just noise and false positivesFP from SAST analysis.

* Fider findings – PR view, full details showing the exploitation impact and payloads.

We will start sharing all the Bright fuzzer findings on a regular basis so follow Bright on all social channels to ongoing updates and stay tuned for my post next week.
