Research-oriented Cybersecurity startup specializing in #fuzzing, Vulnerability Research & Offensive security on Mobile, Browser, AI/LLM, Network & Blockchain.

Paris
💥 We’ve just raised €1M in pre-seed funding to accelerate the development of FuzzForge. When I started FuzzingLabs, everything was bootstrapped: our audits, our trainings, our R&D. No investors, no funding. Just a passionate team obsessed with offensive security and the belief that we could build something different. Three years later, we’re 30 and we are now entering a new chapter. This funding will allow us to: - accelerate the open-source development of FuzzForge, - build its marketplace of agents and workflows, - and expand the SaaS version to automate vulnerability research at scale. A huge thanks to @class_lambda and @ergodicgroup for their strategic support and trust in our vision: --> making offensive security more intelligent, collaborative, and automated. FuzzForge is already open source and under active development. You can check it out here: 🔗 github.com/FuzzingLabs/fuzzf…
5
40
266
21,017
A file in the Linux kernel with 0% Syzbot coverage is an invitation... That's how our team at @fuzzinglabs ended up looking in batman-adv, the mesh networking subsystem (B.A.T.M.A.N. = Better Approach To Mobile Ad hoc Networking). Nobody had ever fuzzed the Linux kernel's mesh networking subsystem from the frame reception side. So we did. Three bugs, one patch now merged in mainline. 🧵
1
6
54
3,570
With the harness up, the first crash came quickly. KASAN report in batadv_iv_ogm_send_to_if, the function that splits aggregated OGMs out of a forward packet.
1
205
Takeaway: public coverage dashboards are a map of where the bugs still are. The gaps are the target list. Full write-up by Alexis & Lyes, crash traces, the Syzlang grammar, the kernel patch: fuzzinglabs.com/fuzzing-batm…
2
5
530
FuzzingLabs is joining #SEAstart, @Gican_InduNav 's accelerator for the French naval industry. We break naval systems before attackers do! We already found 6 CVEs across the maritime navigation stack (GNSS/RTK, AIS, NMEA 2000), several with no auth required. Looking for naval design partners. Let's talk. #Cybersecurity #NavalDefense #SEAstart
3
18
2,006
Cryptography on embedded devices: picking AES vs Ascon is the easy part. The hard part? Where keys live, whether the chip has any trustworthy RNG, if it can persist a nonce counter, and which accelerator you're forced to use. Our 101 guide 👇 fuzzinglabs.com/crypto-embed…
2
5
19
1,800
FuzzingLabs retweeted
🛠️ [POC2026] TRAINING Apple’s Swift - RE, VR and AI by Atlan Pinabel & Nabih Benazzouz (@FuzzingLabs) 📅 Nov 9-11 (3 days) 📍 The Westin Seoul Parnas, Korea Detail 👉 powerofcommunity.net/#traini… #POC2026
2
10
1,859
Our CEO @Pat_Ventuzelo opened @_leHACK_ 2026, France's biggest hacking con, with his keynote: "No need to be a Mythos to do offensive security." You don't need a classified frontier model. The moat moved from model access to the harness and the building blocks are already in your hands. Slides 👇 You don't have to be a Mythos. You just have to keep building. fuzzinglabs.com/wp-content/u…
6
25
2,361
🛰️ We broke RTKLIB, the open-source engine behind centimeter-accurate GPS in drones, boats, autonomous vehicles & survey networks. 4 memory-corruption bugs in its RTCM3 / RINEX decoders. No auth. Reachable from a single crafted correction stream or one booby-trapped file. 1 OOB write + 3 OOB reads. A rogue NTRIP caster or a MITM'd stream is enough to crash or corrupt the positioning stack of a machine that moves itself. Reported upstream, coordinated disclosure (RTKLIB #796–799). Full write-up 👇 fuzzinglabs.com/breaking-rtk…
13
28
2,484
Excited to be there end of the year !! Looking forward to show to the community what we have build with fuzzforge, our ai agents orchestration platform for embedded security !
Excited to welcome @FuzzingLabs as an Exhibit Sponsor for Hardwear.io Netherlands 2026. 🚀 Looking forward to having their team and research expertise. Registrations & CFPs now live: hardwear.io/nl-2026/cfp/?utm… #HardwearNL2026 #ExhibitSponsor
1
1
5
1,617
🚀 FuzzingLabs has joined the OVHcloud Startup Program. This will help us scale #FuzzForge, our platform orchestrating specialized AI agents for continuous offensive validation on firmware, binaries, and embedded systems, on sovereign European cloud infrastructure. Aligned with what our customers in defense, industrial, and critical sectors need: sovereign, European & CRA-ready by design. Thanks to the OVHcloud team for the support. #Cybersecurity #AI #SovereignCloud #OVHcloud #FuzzForge
3
16
1,292
🚀 FuzzingLabs is now part of the @NVIDIA Inception Program! We're building FuzzForge, our AI agents platform leveraging GPU infrastructure for Continuous Offensive Validation on firmware, binaries & embedded systems. Scaling fine-tuned Qwen, Gemma & DeepSeek for offensive security. 🔥 #NVIDIAInception #AI #Cybersecurity
3
41
2,529
We have been selected to join the Cyber Defense Factory, a program run by the French Ministry of Armed Forces. This is a concrete validation of what we've been building with FuzzForge and a chance to test it on defense-grade use cases, working directly with DGA teams. Six months of hands-on work, real targets, real feedback from people who know exactly what vulnerability detection security tools need to deliver. Thank you to @DGA - Direction générale de l'armement, COMCYBER and the Agence de l'innovation de défense for making this possible. Excited for what's ahead. 🔥
9
28
3,078
Last week at @offensive_con 2026, @_Noiche and @Pat_Ventuzelo presented "Navigating the MTE Landscape: iOS Memory Protection Deep Dive" A tour through Apple's MIE: (E)MTE internals, XNU integration, kernel zalloc tagging policy, and the new XZone malloc in userland. Slides 👇 fuzzinglabs.com/wp-content/u… #OffensiveCon #iOS #MTE
1
32
132
19,779
We got the email too. We had a working RCE on Oracle Autonomous AI Database ready to demonstrate live at #Pwn2Own Berlin next week. ZDI confirmed they're at maximum capacity and can't add extra contest days. AI is now generating offensive capability faster than the institutions built to process it can keep up. We'll be in Berlin May 14-16 regardless. The conversations there will be really interesting!
‼️🚨 Pwn2Own Berlin 2026 just hit a wall. For the first time in 19-years, ZDI rejected dozens of working zero-day RCE submissions because organizers ran out of contest slots. Rejected hackers are now going public with PoC demos and direct vendor disclosures, breaking Pwn2Own's usual secrecy. ▪️ AI surfaces a massive wave of 0-day RCEs. ▪️ Submissions overwhelm ZDI past max capacity. ▪️ Slots run out. Researchers with working chains get rejected. ▪️ "Revenge disclosures" begin. ← we are here. Confirmed casualties so far: ▪️ @xchglabs : 86 vulnerabilities prepared (PyTorch, NVIDIA, Linux KVM, Oracle, Docker, Ollama, Chroma, LiteLLM, llama.cpp). All rejected. Now reporting directly to vendors with writeups dropping as patches land. ▪️ @ggwhyp : full-chain Firefox RCE on Windows. Rejected. Publicly demoed (HTML page → cmd.exe → calc.exe). Responsibly disclosed to Mozilla. ▪️ @yunsu_dev : working RCE chain, rejected. Submitting elsewhere. ▪️ @ryotkak : tried to register for 3+ weeks. ZDI confirmed "at maximum capacity, can't add extra contest days." Considered canceling flight and hotel. ▪️ @anzuukino2802 : Claude Code RCE PoC. Rejected. ▪️ @desckimh : 0-day RCEs in Ollama and LM Studio. Rejected. Reported impact: a community-estimated 150+ researchers tried to register. Accepted contestants are now being warned about collisions. Rejected vulnerabilities going to bug bounty programs may trigger pre-event patches that invalidate the work of those who got in. ZDI has not publicly addressed the capacity issue. The event still runs May 14-16 in Berlin.
3
34
238
45,195
Our team found a Poseidon hash collision in Solana's Agave VM crypto syscall. Two distinct byte inputs → same field element → same Poseidon output. Affects both Agave and Firedancer via implicit padding paths. Full write-up: fuzzinglabs.com/solana-agave… Good job by @Ectari0
Made with AI
3
14
70
5,727
New training is live: Reversing Modern Binaries - Practical Rust & Go Analysis 4 days, hands-on, built from real malware (Luca Stealer & others). Battle-tested at POC & REcon. 🎟️ Launch -20% with REVERSE20 Prefer in-person? See you at REcon Montreal 🇨🇦 👉 academy.fuzzinglabs.com/reve…
2
13
1,626