📝 Blog

Insights, updates, and stories from the BUGATTI team.

Securing the Engine: Attacking and Defending GitHub Actions Pipelines

June 11, 2026 • by G. R. Benedetti and N. Van Es (VUB-Soft)

A structural primer on GitHub Actions security, common CI/CD pipeline attack paths, and practical hardening measures for embedded software teams.

Read more →

Onweer: Leveraging Fuzzing for Automated Chaos In Testing

April 20, 2026 • by G. Coremans (VUB-Soft)

Onweer combines REST API fuzzing with fault injection to automatically discover resilience bugs that conventional testing misses.

Read more →

The False Positive Flood: Six Insights for CVE Triage in Embedded Systems

November 27, 2025 • by J. Lapon (KU Leuven DistriNet)

Understanding why vulnerability scanners produce overwhelming false positive alerts and how to effectively triage CVE results in embedded systems.

Read more →