CA-SHIFTLEFT
17.11.2021 09:02:09 CET | Business Wire | Press release
ShiftLeft, Inc ., an innovator in automated application security testing, today announced that its Chief Scientist, Fabian Yamaguchi, and Security Research Engineer, Claudiu-Vlad Ursache, will give a presentation focused on Ghidra2cpg at the No Hat Conference in Bergamo, Italy on November 20, 2021. The No Hat 2021 is a security conference organized to bring together specialists, professionals and hobbyists operating in the field of computer security and privacy.
Event Details:
Who:
Fabian Yamaguchi, Chief Scientist and Claudiu-Vlad Ursache, Security Research Engineer, ShiftLeft
What:
Virtual Session: Presentation on Ghidra2cpg: From graph queries to vulnerabilities in binary code
When:
Saturday, November 20, 2021, 11:15am – 12:00pm CET
Where:
Centro Congressi Giovanni XXIII - Bergamo, Italy
For more information, visit : https://www.nohat.it/program
Session Abstract - Ghidra2cpg: From graph queries to vulnerabilities in binary code
Uncovering bugs in source code is hard enough as it is, but when all you have is a binary, the importance of tooling becomes undeniable. Disassemblers such as IDA Pro, Ghidra, BinaryNinja or Radare2 provide a strong foundation for an investigation but are designed primarily to assist in what remains a manual investigation. This leaves room for partial automations that make the discovery process less painful.
Fabian and Claudiu were looking to design a search tool for binary code that allows them to uncover instances of programming patterns linked to vulnerabilities - at scale and for multiple major instruction sets. In this talk, they will present ghidra2cpg, an extension for the open-source code mining platform Joern that enables it to process binary code. Together, Joern and ghidra2cpg enable you to quickly uncover the attack surface, search for variants of known vulnerabilities, and gather information interactively using a query language.
In this session they will show how to write queries for the system that describe bugs in source code and introduce corresponding queries for binary code, highlighting what's harder and what is easier to describe when looking at the machine code directly. They will also be looking at modern consumer-grade router firmware and may drop a zero-day or two in the process.
About Fabian Yamaguchi
Fabian is Chief Scientist at ShiftLeft Inc and an Associate Professor Extraordinary at Stellenbosch University. He has over 15 years of experience in the security domain, where he has worked as a security consultant and researcher, focusing on manual and automated vulnerability discovery. Throughout his work, he has identified previously unknown vulnerabilities in popular system components and applications such as the Microsoft Windows kernel, the Linux kernel, the Squid proxy server, and the VLC media player. He has presented his findings and techniques at both major industry conferences such as BlackHat USA, DefCon, First, and CCC, and renowned academic security conferences such as ACSAC, Security and Privacy, and CCS. He holds a master’s degree in computer engineering from Technical University Berlin, as well as a PhD in computer science from the University of Goettingen.
About Claudiu-Vlad Ursache
Claudiu-Vlad Ursache is a Security Research Engineer at ShiftLeft, having recently entered cybersecurity after a decade of writing software. In his day-to-day job he builds static analysis tools and his current research focuses on IoT firmware.
About ShiftLeft
ShiftLeft enables software developers and application security teams to radically reduce the attackability of their applications by providing near-instantaneous security feedback on software code during every pull request. By analyzing application context and data flows in near real-time with industry leading accuracy, ShiftLeft empowers developers and appsec team to find and fix the most serious vulnerabilities faster. Using its patented graph analysis that combines code attributes and analyzes actual attack paths based on real application architecture, ShiftLeft’s platform scans for attack context and pathways typical of modern applications, across APIs, OSS, internal microservices and first-party business logic code, and then provides detailed guidance on risk remediation within existing development workflows and tooling. ShiftLeft CORE, a unified code security platform, combines the company’s flagship NextGen Static Analysis (NG SAST), Intelligent Software Composition Analysis (SCA), and contextual security training through ShiftLeft Educate to provide developers and application security teams the fastest, most accurate, most relevant, and easiest to use automated application security and code analysis platform.
Backed by Bain Capital Ventures, Mayfield, Thomvest Ventures, and SineWave Ventures, ShiftLeft is based in Santa Clara, CA. To learn how ShiftLeft keeps AppSec in sync with the rapid pace of DevOps, see https://www.shiftleft.io/ .
View source version on businesswire.com: https://www.businesswire.com/news/home/20211117005403/en/
Link:
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
NetApp Wins 2026 Google Cloud Infrastructure Modernization Partner of the Year for Storage21.4.2026 21:00:00 CEST | Press release
NetApp® (NASDAQ: NTAP), the Intelligent Data Infrastructure company, today announced that it has received the 2026 Google Cloud Infrastructure Modernization Partner of the Year for Storage Award. NetApp is being recognized for its achievements in the Google Cloud ecosystem, helping joint customers modernize their infrastructure and run enterprise workloads on Google Cloud using Google Cloud NetApp Volumes. “The Google Cloud Partner Awards honor the strategic innovation and measurable value our partners bring to customers,” said Kevin Ichhpurani, President, Global Partner Ecosystem and Channels, Google Cloud. “We are proud to name NetApp a 2026 Google Cloud Partner Award winner, celebrating their role in driving customer success over the last year.” The Google Cloud Infrastructure Modernization Partner of the Year for Storage Award recognizes partners that have helped their customers modernize their infrastructure by leveraging Google Cloud's innovative solutions, resulting in increased
Adtran and GLDS expand partnership to deliver billing-driven, zero-touch automation for subscriber lifecycle management21.4.2026 20:00:00 CEST | Press release
News summary: Service providers need simpler, billing-integrated automation to streamline activation, manage Wi-Fi and cut operational complexity Adtran’s Intellifi® managed Wi-Fi works with GLDS BroadHub®, enabling zero-touch automation from order entry through lifecycle management Solution reduces operational complexity, accelerates time to revenue and preserves operator control within an open ecosystem Adtran today announced a new phase in its long-standing partnership with GLDS, delivering billing-driven, zero-touch automation for subscriber lifecycle management. As broadband and managed Wi-Fi services scale, manual hand-offs between billing, OSS and in-home networking systems are no longer sustainable. By enabling GLDS BroadHub® to orchestrate subscriber creation, service activation and ongoing lifecycle changes across access and the connected home, the solution streamlines operations, accelerates time to revenue and reduces operational complexity. This approach gives broadband pr
Unleashing GEN4: a New Era of High-performance, Sustainable Electric Racing Begins21.4.2026 17:54:00 CEST | Press release
The debut of the GEN4 race car underlines a step change in electric racing performance. Set for its competitive debut in the 2026/27 Season, the GEN4 machine has a 71% increase in power. More road-relevant than ever, many of the biggest OEMs will take these innovations from track to road. The Fédération Internationale de l'Automobile (FIA) and Formula E have unleashed the GEN4 car on track in its debut run in the South of France, signalling the beginning of a new era for electric motor sport. This all-new car will be raced in the 2026/27 Season of the ABB FIA Formula E World Championship. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260421618886/en/ Unleashing GEN4: A new era of high-performance, sustainable electric racing begins Capable of speeds over 335kph (208mph), 0-100kph in approximately 1.8s, and 0-200kph in just 4.4s - 1.5s faster than its predecessor. GEN4 produces up to 600kW of power, a 71% increase in base ou
Resale on the Rise: Klarna's Resell Feature Grows 75% as Consumers Put Real Money Back in Their Pockets21.4.2026 17:00:00 CEST | Press release
New data from Klarna reveals consumers are making an estimated $137 per sold item as resale becomes a go-to financial habit New data from Klarna,the global digital bank and flexible payments provider, reveals that its in-app resell feature is gaining significant momentum:listings created through the app grew by up to 75% over the past 13 months*, as consumers increasingly turn to resale as a way to earn real money from items they already own. The data points to a broader shift in financial behaviour: consumers are increasingly treating the things they own not as fixed costs, but as assets with ongoing value. Reselling is becoming routine, not a one-off First launched in Sweden in 2022, Klarna's resell feature is now available across 15 markets, letting users list items for resale directly from their purchase history via leading resale marketplaces such as eBay, Poshmark and Tradera. No need to remember what they paid, find the receipt, or switch to another app. Klarna pre-fills key lis
Frasca Pilatus PC-12 PRO Flight Training Device Receives FOCA Qualification21.4.2026 16:05:00 CEST | Press release
Training device developed for the Pilatus PC-12 PRO with Garmin’s G3000 PRIME Integrated Flight Deck Frasca International, Inc., a FlightSafety International company and global leader in flight simulation, today announced that its Pilatus PC-12 PRO Flight Simulation Training Device (FSTD) received Level 2 Flight Training Device (FTD2) and Flight and Navigation Procedures Trainer (FNPT II) qualification from Switzerland’s Federal Office of Civil Aviation (FOCA). Frasca is the first to develop a PC-12 PRO training device. The device equipped with Garmin’s G3000 PRIME Avionics suite is installed at Pilatus Aircraft Ltd headquarters in Stans, Switzerland, where it will support training for the next generation of PC-12 pilots. The qualification enables pilots to complete a wide range of instruments, procedural and advanced systems training in a highly immersive environment that mirrors the capabilities of the aircraft. “The PC-12 PRO leads the way with advanced features, and we’re proud to
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
