ShiftLeft to Present at No Hat Conference 2021
17.11.2021 11:00:00 EET | Business Wire | Press release
ShiftLeft, Inc., an innovator in automated application security testing, today announced that its Chief Scientist, Fabian Yamaguchi, and Security Research Engineer, Claudiu-Vlad Ursache, will give a presentation focused on Ghidra2cpg at the No Hat Conference in Bergamo, Italy on November 20, 2021. The No Hat 2021 is a security conference organized to bring together specialists, professionals and hobbyists operating in the field of computer security and privacy.
Event Details:
Who: Fabian Yamaguchi, Chief Scientist and Claudiu-Vlad Ursache, Security Research Engineer, ShiftLeft
What: Virtual Session: Presentation on Ghidra2cpg: From graph queries to vulnerabilities in binary code
When: Saturday, November 20, 2021, 11:15am – 12:00pm CET
Where: Centro Congressi Giovanni XXIII - Bergamo, Italy
For more information, visit: https://www.nohat.it/program
Session Abstract - Ghidra2cpg: From graph queries to vulnerabilities in binary code
Uncovering bugs in source code is hard enough as it is, but when all you have is a binary, the importance of tooling becomes undeniable. Disassemblers such as IDA Pro, Ghidra, BinaryNinja or Radare2 provide a strong foundation for an investigation but are designed primarily to assist in what remains a manual investigation. This leaves room for partial automations that make the discovery process less painful.
Fabian and Claudiu were looking to design a search tool for binary code that allows them to uncover instances of programming patterns linked to vulnerabilities - at scale and for multiple major instruction sets. In this talk, they will present ghidra2cpg, an extension for the open-source code mining platform Joern that enables it to process binary code. Together, Joern and ghidra2cpg enable you to quickly uncover the attack surface, search for variants of known vulnerabilities, and gather information interactively using a query language.
In this session they will show how to write queries for the system that describe bugs in source code and introduce corresponding queries for binary code, highlighting what's harder and what is easier to describe when looking at the machine code directly. They will also be looking at modern consumer-grade router firmware and may drop a zero-day or two in the process.
About Fabian Yamaguchi
Fabian is Chief Scientist at ShiftLeft Inc and an Associate Professor Extraordinary at Stellenbosch University. He has over 15 years of experience in the security domain, where he has worked as a security consultant and researcher, focusing on manual and automated vulnerability discovery. Throughout his work, he has identified previously unknown vulnerabilities in popular system components and applications such as the Microsoft Windows kernel, the Linux kernel, the Squid proxy server, and the VLC media player. He has presented his findings and techniques at both major industry conferences such as BlackHat USA, DefCon, First, and CCC, and renowned academic security conferences such as ACSAC, Security and Privacy, and CCS. He holds a master’s degree in computer engineering from Technical University Berlin, as well as a PhD in computer science from the University of Goettingen.
About Claudiu-Vlad Ursache
Claudiu-Vlad Ursache is a Security Research Engineer at ShiftLeft, having recently entered cybersecurity after a decade of writing software. In his day-to-day job he builds static analysis tools and his current research focuses on IoT firmware.
About ShiftLeft
ShiftLeft enables software developers and application security teams to radically reduce the attackability of their applications by providing near-instantaneous security feedback on software code during every pull request. By analyzing application context and data flows in near real-time with industry leading accuracy, ShiftLeft empowers developers and appsec team to find and fix the most serious vulnerabilities faster. Using its patented graph analysis that combines code attributes and analyzes actual attack paths based on real application architecture, ShiftLeft’s platform scans for attack context and pathways typical of modern applications, across APIs, OSS, internal microservices and first-party business logic code, and then provides detailed guidance on risk remediation within existing development workflows and tooling. ShiftLeft CORE, a unified code security platform, combines the company’s flagship NextGen Static Analysis (NG SAST), Intelligent Software Composition Analysis (SCA), and contextual security training through ShiftLeft Educate to provide developers and application security teams the fastest, most accurate, most relevant, and easiest to use automated application security and code analysis platform.
Backed by Bain Capital Ventures, Mayfield, Thomvest Ventures, and SineWave Ventures, ShiftLeft is based in Santa Clara, CA. To learn how ShiftLeft keeps AppSec in sync with the rapid pace of DevOps, see https://www.shiftleft.io/.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20211117005403/en/
Contact information
PR:
Corinna Krueger
ShiftLeft
ckrueger@shiftleft.io
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
FlexGen Launches International Operations, Delivering Software and Services to Meet Demand for Battery Storage in Europe17.6.2026 15:00:00 EEST | Press release
FlexGen Power Systems, LLC. ("FlexGen"), a leading battery energy storage solution and energy management software provider, announced today that it continues to grow its global business by building its presence in Europe to increase battery storage capacity on local grids, supporting energy reliability and affordability. FlexGen offers its energy management system, including power plant controls (PPC), analytics, and site-level supervisory control and data acquisition (SCADA), as well as services, such as lifecycle services, integration abilities, and data centre leadership, to the European market to improve operational performance, increase availability, and unlock greater returns for battery storage developers and operators. “As Europe faces rising energy prices, high curtailment rates, and rising demand from electrification, FlexGen’s advanced software and services will meet local grid challenges and solve for energy independence, reliability, and affordability,” said Mike Wallace,
Moody’s Launches Decision-Grade AI Skills for Major AI Platforms17.6.2026 15:00:00 EEST | Press release
Moody’s Corporation (NYSE: MCO) today announced the release of its first set of AI skills – purpose-built, platform-agnostic instruction kits that encode Moody’s analytical frameworks and connect AI agents to its decision-grade intelligence. Available across compatible AI platforms beginning with Microsoft 365 Copilot Cowork, Moody’s skills enable customers to execute complex analytical workflows through a single natural-language request, with outputs grounded in Moody’s proprietary ratings, research, and risk intelligence. “Moody’s is among the first financial data providers to deliver a full library of skills on an open standard, and today’s launch is just the beginning,” said Cristina Pieretti, Head of Digital Content and Innovation at Moody’s. “AI platforms are becoming the interface for financial decision-making, and the next phase of adoption will be defined by execution. Skills are how we encode Moody’s expertise into that execution layer.” Skills are emerging as the standard fo
Rehlko and Liebherr Partner on Strategic Capacity Expansion to Support Accelerating Data Center Demand for Resilient Power Solutions17.6.2026 15:00:00 EEST | Press release
Rehlko, a global energy resilience leader delivering innovative solutions across industrial energy systems, powertrain technologies, and home energy applications, joined Liebherr Group (“Liebherr”) on June 2 for the strategic capacity expansion ceremony at the Liebherr-Components facility in Colmar, France. This event marks a key milestone in the continued expansion of Rehlko’s strategic partnership with Liebherr and a significant step in scaling resilient power solutions for the next generation of digital infrastructure. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260617213506/en/ Liebherr and Rehlko celebrate the strategic capacity expansion of Liebherr-Components Colmar factory. From left to right: Brian Melka (President and CEO of Rehlko), Jan Liebherr (President of the Administrative Board of Liebherr-International AG), Pietro Iemmi (CEO Liebherr-Component Technologies AG), and further members of Rehlko’s and Liebher
Thredd and Sutton Bank Partner to Power U.S. Card Program Expansion for Global Brands17.6.2026 15:00:00 EEST | Press release
Thredd, the AI-first issuer processing platform, today announced a strategic partnership with Sutton Bank, a leading sponsor bank and card issuer for fintechs and embedded finance use cases. Through the partnership, Sutton Bank will serve as a BIN sponsor for Thredd clients seeking to launch and scale prepaid and debit card programs in the United States. The partnership strengthens the U.S. market proposition for global fintechs and embedded finance providers by providing these organizations access to an established U.S. issuing bank partner with a long-standing track record supporting card programs across the fintech ecosystem. Sutton Bank has become widely recognized for its payments business, including its work with card networks, processors and program managers, as well as its role as a large BIN sponsor for the fintech community. Together, Thredd and Sutton Bank will support companies looking to bring modern prepaid and debit card programs to market across the U.S. Thredd will pro
FEINDEF 27 Accelerates Commercialisation, Surpassing FEINDEF 25’s Total Exhibition Area by 25% With One Year to Go17.6.2026 14:41:00 EEST | Press release
One year ahead of FEINDEF 27, FEINDEF, Spain’s International Defence and Security Exhibition, continues to maintain a strong commercialisation pace, outperforming previous editions at the same stage. The exhibition has already surpassed the total exhibition area occupied at FEINDEF 25 by 25%, reflecting the strong interest across the sector in participating in the next edition and reinforcing its appeal amid the continued growth of the defence and security industry. Organised by the Fundación Feindef, the exhibition will hold its fifth edition from 18 to 20 May 2027 at IFEMA Madrid, with the objective of consolidating a new phase of growth and strengthening its position as a leading international platform bringing together institutions, industry stakeholders and professionals from across the defence and security ecosystem. In this context, FEINDEF 27 is expected to exceed 89,000 m² of total exhibition area, representing a 46% increase compared to FEINDEF 25 and expanding its capacity t
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
