Jonathan Metzman Profile
Jonathan Metzman

@metzmanj

Followers
2K
Following
5K
Media
13
Statuses
954

I do fuzzing on Google's Open Source Security Team. I work on OSS-Fuzz/ClusterFuzz/FuzzBench. Speaking on behalf of myself, not my employer.

Joined January 2019
Don't wanna be here? Send us removal request.
@metzmanj
Jonathan Metzman
2 years
Check out our work on using LLMs to generate fuzz targets in OSS-Fuzz: https://t.co/plaK7jLUPv
3
30
132
@argvee
Heather Adkins - Ꜻ - Spes consilium non est
12 days
We’re excited to see the security and OSS communities engage on vulnerability disclosure in light of new AI technologies that we believe will enable both defenders and attackers alike. Existing and emerging norms around disclosure are important debates, and we’ve noted the
7
37
112
@R00tkitSMM
Meysam
14 days
Apple patched six WebKit CVEs found by Google Big Sleep in iOS 26.1. https://t.co/IrTTUj8OvB
support.apple.com
This document describes the security content of iOS 26.1 and iPadOS 26.1.
5
16
103
@argvee
Heather Adkins - Ꜻ - Spes consilium non est
16 days
Really great update from the DeepMind Code Mender project and their journey in writing safe code. Some great results so far. A ways to go!
Tweet card summary image
deepmind.google
Using advanced AI to fix critical software vulnerabilities
0
5
14
@ifsecure
Ivan Fratric 💙💛
19 days
Although the target might not be as impactful as some others we ran against, these bugs in QuickJS are some of my favorite Big Sleep finds, because they demonstrate the ability of LLMs to reason about and detect classic JavaScript engine vulnerabilities.
3
9
61
@ifsecure
Ivan Fratric 💙💛
3 months
https://t.co/TeYPpUANyW now with even more bugs. Also great to see the first ones getting fixed, including in v8, ANGLE and imagemagick.
3
13
96
@ifsecure
Ivan Fratric 💙💛
3 months
If you've been keeping track on the Big Sleep bug tracker at https://t.co/TeYPpUANyW you might have noticed it lists more bugs now compared to last week. Including a "High impact issue in V8" :)
3
21
102
@elie
Elie Bursztein
3 months
While insider attacks are a major risk, there’s little knowledge sharing in the community on this topic. To address this gap, today at Black Hat we presented FACADE, the high-precision anomaly detection system that we’ve used at Google since 2018 to accurately detect insider
0
6
9
@ifsecure
Ivan Fratric 💙💛
4 months
Big Sleep goes brrr
@argvee
Heather Adkins - Ꜻ - Spes consilium non est
4 months
Today as part of our commitment to transparency in this space, we are proud to announce that we have reported the first 20 vulnerabilities discovered using our AI-based "Big Sleep" system powered by Gemini —
1
2
26
@JohnHultquist
John Hultquist
4 months
TWENTY!
@argvee
Heather Adkins - Ꜻ - Spes consilium non est
4 months
Today as part of our commitment to transparency in this space, we are proud to announce that we have reported the first 20 vulnerabilities discovered using our AI-based "Big Sleep" system powered by Gemini —
1
2
7
@Kent_Walker
Kent Walker
4 months
Our cybersecurity AI Agent Big Sleep is proving to be an invaluable tool in protecting our digital world. It’s already uncovered 20 vulnerabilities unknown to defenders. That’s 20 gaps that bad actors won’t be able to exploit.
@argvee
Heather Adkins - Ꜻ - Spes consilium non est
4 months
Today as part of our commitment to transparency in this space, we are proud to announce that we have reported the first 20 vulnerabilities discovered using our AI-based "Big Sleep" system powered by Gemini —
0
5
18
@royalhansen
Royal Hansen
4 months
Initial results from a large scale run of @Google Big Sleep are here!Our AI agent found a series of vulnerabilities in widely used & reviewed software,demonstrating a new frontier in automated vulnerability discovery.Full details once the issues are fixed:
1
4
28
@argvee
Heather Adkins - Ꜻ - Spes consilium non est
4 months
Today as part of our commitment to transparency in this space, we are proud to announce that we have reported the first 20 vulnerabilities discovered using our AI-based "Big Sleep" system powered by Gemini —
17
73
283
@ForrestPKnight
Forrest
6 months
you're not allowed to write comments in your code anymore, because if you do everyone will just think it's ai generated.
473
510
11K
@robertswiecki
Robert Swiecki
8 months
honggfuzz alive and kicking. stack based buffer overflow in libxml2 -
0
19
86
@Davkorcz
David Korczynski
9 months
Auto generating #fuzzing harnesses by way of program analysis and #LLMs! New blog post "Minimal LLM-based fuzz harness generator": https://t.co/hZoXyZvXz6 We show how you can generate a sophisticated fuzz harness synthesis tool with a few lines of code.
0
21
110
@mboehme_
Marcel Böhme👨‍🔬
9 months
#FUZZING'25 CALL FOR PAPERS ────── ✨ New OC members: @RuijieMeng (NUS) + Rohan Padhye (@moarbugs; CMU). ✨ New paper type: Fuzzing Nuggets (short papers). 🔗 https://t.co/cOJM2fvBlp 📅 20. March (Submission) //cc @YannicNoller (RUB), László Szekeres (@lszekeres; Google)
2
19
53
@mboehme_
Marcel Böhme👨‍🔬
9 months
ICLR'25 Spotlight 🤩 (5% of accepted papers) -- for a topic we've just been nerding out on. Congrats Seongmin! 🎉 📝
@mboehme_
Marcel Böhme👨‍🔬
10 months
Just got our first @ICLR_conf paper accepted! 🥳🥳 It shines light on a beautiful riddle! Suppose, you're drawing balls from an urn with an unknown distribution of colors. What is the proportion of balls with colors, you've never seen? Led by Seongmin (@nim_gnoes_eel).
5
4
50
@metzmanj
Jonathan Metzman
10 months
The original link I posted for the OSS-Fuzz PhD internship was wrong, sorry to folks who applied to the research intern position. Please re-apply to the one below. The correct one is for the SWE intern position. 🤦
@metzmanj
Jonathan Metzman
10 months
0
5
14
@metzmanj
Jonathan Metzman
10 months
0
0
4
@mboehme_
Marcel Böhme👨‍🔬
10 months
If I was still a PhD, I would definitely take this opportunity. So much opportunity for real impact!
@metzmanj
Jonathan Metzman
10 months
The OSS-Fuzz team is hiring a PhD intern for this summer. Come join us and build the future of fuzzing. Link in next tweet in thread. RTs appreciated!
1
4
33