Mayhem Blog

How Fuzzing Redefines Application Security

How Fuzzing Redefines Application Security

The Application Security Testing market is highly fragmented. From SAST to DAST to SCA to IAST to RASP, what is the best? Our answer: Autonomous testing through fuzz testing and symbolic execution.
Satisfy 5 DoD DevSecOps Requirements with One Tool

Satisfy 5 DoD DevSecOps Requirements with One Tool

DevSecOps is enabling the Department to develop quickly and securely, so organizations can continuously meet critical and urgent needs of the warfighter.
Leveraging Fuzz Testing to Achieve ED-203A / DO-356A

Leveraging Fuzz Testing to Achieve ED-203A / DO-356A

Aerospace must continually and proactively find and fix security and safety issues. Learn how to achieve DO-356A / ED-203A compliance.
Addressing the Spectrum of Risks

Addressing the Spectrum of Risks

In this blog, we’ll walk through the spectrum of risk and the types of solutions that are strongest at addressing each risks.
Why You Need Test and Evaluation (T&E)

Why You Need Test and Evaluation (T&E)

In part three of the series, I will discuss the role of test and evaluation in your organization.
The Risks In Using Third-Party Code

The Risks In Using Third-Party Code

Vulnerabilities can be inherited through your software supply chain, and it’s more common than we may like to admit.
Securing Your Software Supply Chain

Securing Your Software Supply Chain

Part one of a three-part series. Applications contain hundreds of code components. Applications are constructed similarly to automobiles: parts are sourced from multiple vendors to produce software that is then used by the consumer.
Back to the Fuzz: Fuzzing for Command Injections

Back to the Fuzz: Fuzzing for Command Injections

Some may remember NCSA HTTPd, a predecessor to Apache. However, what they might not know (but won't be surprised by!) is that it had plenty of bugs. Let's dive in and reproduce a classic command injection with fuzzing!
Useful Properties To Check With Fuzz Testing

Useful Properties To Check With Fuzz Testing

The is part three of a three part series on Property-based Fuzz Testing. This article lists a number of useful properties that are commonly used to validate the correctness and safety of code. If you are not sure how to apply property-based fuzzing to your code, this list should give you some inspiration.

How about some Mayhem in your inbox?

Subscribe to our monthly newsletter for expert insights and news on DevSecOps topics, plus Mayhem tips and tutorials.

By subscribing, you're agreeing to our website terms and privacy policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Add Mayhem to Your DevSecOps for Free.

Engineer with VR goggles