I'd like to introduce Kuna, a new Rust-based decompiler that explores a highly experimental direction: self-refining decompiler development and usage. Or: a decompiler constantly improved by agents, made for agents. Kuna rivals the best in structuring now. Let's talk about it.1/
Moritz Schloegel
@mu00d8.bsky.social
Faculty @CISPA Helmholtz Center doing software security, program analysis, and fuzzing Previously at SEFCOM lab @ASU and @RUB
Introducing ReproDB—search thousands of research artifacts in seconds. Discover by topic, author, institution, or venue. Built on data from sys/secartifacts, enriched with GitHub stats & citations. Open-source & free. reprodb.github.io
📢 We hit snooze! You have until June 30th to get your paper in. 📄
NDSS 2027 is looking for volunteers to join the Artifact Evaluation Committee (AEC). If you care about reproducibility & open science, we would be glad to have you on board. All sorts of backgrounds welcome & no prior experience required. Interested? Self-nominate here: forms.gle/3UydnaYP6vUC...
Self-nomination for the Artifact Evaluation Committee of NDSS 2027
We are looking for members for the Artifact Evaluation Committee (AEC) of NDSS 2027. The Network and Distributed System Security (NDSS) symposium adopted an Artifact Evaluation (AE) process allowing ...
forms.gle
Can we translate all C to Rust? The susceptibility of C to memory corruption has long been a cybersecurity pain point, and coding agents can free us of it. Read on for my recent experiments in this space, and apt & docker repos that you can pull rust-converted libraries from!
MetaCRiSP’s deadline got pushed back a week to Feb 19 AoE - you’ve got 10 days!
Call for Papers: MetaCRiSP Workshop (Security & Privacy). A venue for metascience and critical reflection on research and peer-review practices in security & privacy. Workshop: May 21, 2026 · San Francisco. (47th IEEE S&P) Deadline: Feb 12, 2026. More here: metacrisp.org @mu00d8.bsky.social
Call for Papers: MetaCRiSP Workshop (Security & Privacy). A venue for metascience and critical reflection on research and peer-review practices in security & privacy. Workshop: May 21, 2026 · San Francisco. (47th IEEE S&P) Deadline: Feb 12, 2026. More here: metacrisp.org @mu00d8.bsky.social
📣 Call for papers! If you're interested in all things metascience, consider submitting to the 1st Workshop on Metascience and Critical Reflections in Security & Privacy (MetaCRiSP), co-located with IEEE S&P. Deadline's Feb 12, AoE. CfP & details: metacrisp.org
MetaCRiSP 2026
metacrisp.org
Happy New Year's Eve! Our tool for placing decompilation (symbols, source, types) into the debugger (gdb) is now officially integrated into pwndbg! You will have access to it (decomp2dbg) in your next default install of pwndbg 🎉 Happy hacking:
Reimplement decompiler integration by k4lizen · Pull Request #3401 · pwndbg/pwndbg
Okay this is a chonker. See the docs/tutorials/decompiler-integration.md for some overview. And docs/assets/caps/decomp_integration_ex.png for an image example vs previous implementation pros we d...
github.com
Do LLMs actually help hackers reverse engineer and understand the software they want to exploit? We ran the first fine-grained human study of LLMs + reverse engineering. To appear at NDSS 2026. Interested? Some quick findings in 🧵👇 Paper: www.zionbasque.com/f...
Must-read for fuzzing folks (read: tooling/algorithms/academia) by Addison Crump addisoncrump.info/research/wha...
What the hell are we doing? · Addison Crump
Homepage for Addison Crump
addisoncrump.info
Interested in #fuzzing the V8 heap sbx? Check out the paper from @nbars.bsky.social et. al. accepted at @acm_ccs 2025. arxiv.org/abs/2509.07757
Empirical Security Analysis of Software-based Fault Isolation through Controlled Fault Injection
We use browsers daily to access all sorts of information. Because browsers routinely process scripts, media, and executable code from unknown sources, they form a critical security boundary between us...
arxiv.org
📢 Excited to announce that the results on BaseBridge, our project on improving cellular baseband emulation, are going public this week. Dyon will present at IEEE S&P on Monday 3pm, while David and I will be on stage at @offensivecon.bsky.social on Saturday 11am with even more details! 1/6
🔥 No fuzz drivers needed. Our paper on injecting greybox fuzzers into running systems at user-defined amplifier points (in-vivo fuzzing) was accepted at #ICSE25! 📝 mboehme.github.io/paper/ICSE25... 🧑💻 github.com/OctavioGalla... (subject to AE) //Lead by Octavio Galland (former #MPI_SP intern).
🔮 ACM TOSEM Perspective Paper on Software Security in 2030 (Invited). 📝 mpi-softsec.github.io/papers/TOSEM... Collab w/ Eric Bodden, Tevfik Bultan, Cristian Cadar, Liu Yang, and Giuseppe Scanniello
Tenure Track @ MPIs in Computer Science (SP, SWS, INF). 🖊️ shlink.mpi-sws.org/faculty 📅 01. December 2024 www.mpi-sp.org/8521/tenure-...
Tenure-Track Openings
mpi-sp.org