Researchers unveil Einstein, tool that auto-generates data-only exploits via syscalls
A research team has released Einstein, an exploitation pipeline that automatically builds data-only attacks by tracking attacker-controllable data flowing into security-sensitive syscall arguments, such as execve or write. Rather than modeling application-specific logic, Einstein works generically against any program's syscall interface, and the team reports it can generate a surprisingly large number of working exploits against real-world software.