ShiftLeft to Present at No Hat Conference 2021
ShiftLeft, Inc., an innovator in automated application security testing, today announced that its Chief Scientist, Fabian Yamaguchi, and Security Research Engineer, Claudiu-Vlad Ursache, will give a presentation focused on Ghidra2cpg at the No Hat Conference in Bergamo, Italy on November 20, 2021. The No Hat 2021 is a security conference organized to bring together specialists, professionals and hobbyists operating in the field of computer security and privacy.
Event Details:
Who: Fabian Yamaguchi, Chief Scientist and Claudiu-Vlad Ursache, Security Research Engineer, ShiftLeft
What: Virtual Session: Presentation on Ghidra2cpg: From graph queries to vulnerabilities in binary code
When: Saturday, November 20, 2021, 11:15am – 12:00pm CET
Where: Centro Congressi Giovanni XXIII - Bergamo, Italy
For more information, visit: https://www.nohat.it/program
Session Abstract - Ghidra2cpg: From graph queries to vulnerabilities in binary code
Uncovering bugs in source code is hard enough as it is, but when all you have is a binary, the importance of tooling becomes undeniable. Disassemblers such as IDA Pro, Ghidra, BinaryNinja or Radare2 provide a strong foundation for an investigation but are designed primarily to assist in what remains a manual investigation. This leaves room for partial automations that make the discovery process less painful.
Fabian and Claudiu were looking to design a search tool for binary code that allows them to uncover instances of programming patterns linked to vulnerabilities - at scale and for multiple major instruction sets. In this talk, they will present ghidra2cpg, an extension for the open-source code mining platform Joern that enables it to process binary code. Together, Joern and ghidra2cpg enable you to quickly uncover the attack surface, search for variants of known vulnerabilities, and gather information interactively using a query language.
In this session they will show how to write queries for the system that describe bugs in source code and introduce corresponding queries for binary code, highlighting what's harder and what is easier to describe when looking at the machine code directly. They will also be looking at modern consumer-grade router firmware and may drop a zero-day or two in the process.
About Fabian Yamaguchi
Fabian is Chief Scientist at ShiftLeft Inc and an Associate Professor Extraordinary at Stellenbosch University. He has over 15 years of experience in the security domain, where he has worked as a security consultant and researcher, focusing on manual and automated vulnerability discovery. Throughout his work, he has identified previously unknown vulnerabilities in popular system components and applications such as the Microsoft Windows kernel, the Linux kernel, the Squid proxy server, and the VLC media player. He has presented his findings and techniques at both major industry conferences such as BlackHat USA, DefCon, First, and CCC, and renowned academic security conferences such as ACSAC, Security and Privacy, and CCS. He holds a master’s degree in computer engineering from Technical University Berlin, as well as a PhD in computer science from the University of Goettingen.
About Claudiu-Vlad Ursache
Claudiu-Vlad Ursache is a Security Research Engineer at ShiftLeft, having recently entered cybersecurity after a decade of writing software. In his day-to-day job he builds static analysis tools and his current research focuses on IoT firmware.
About ShiftLeft
ShiftLeft enables software developers and application security teams to radically reduce the attackability of their applications by providing near-instantaneous security feedback on software code during every pull request. By analyzing application context and data flows in near real-time with industry leading accuracy, ShiftLeft empowers developers and appsec team to find and fix the most serious vulnerabilities faster. Using its patented graph analysis that combines code attributes and analyzes actual attack paths based on real application architecture, ShiftLeft’s platform scans for attack context and pathways typical of modern applications, across APIs, OSS, internal microservices and first-party business logic code, and then provides detailed guidance on risk remediation within existing development workflows and tooling. ShiftLeft CORE, a unified code security platform, combines the company’s flagship NextGen Static Analysis (NG SAST), Intelligent Software Composition Analysis (SCA), and contextual security training through ShiftLeft Educate to provide developers and application security teams the fastest, most accurate, most relevant, and easiest to use automated application security and code analysis platform.
Backed by Bain Capital Ventures, Mayfield, Thomvest Ventures, and SineWave Ventures, ShiftLeft is based in Santa Clara, CA. To learn how ShiftLeft keeps AppSec in sync with the rapid pace of DevOps, see https://www.shiftleft.io/.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20211117005403/en/
Contact information
PR:
Corinna Krueger
ShiftLeft
ckrueger@shiftleft.io
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Ant International Upgrades Antom Copilot to Advance Domain-Specific Agentic AI to Solve Global Payment Complexity1.12.2025 08:21:00 EET | Press release
Antom, a leading merchant payment and digitisation services provider under Ant International, today announced major upgrades to Antom Copilot, its industry-first AI agent designed for merchant payment and operations management. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251130027598/en/ Antom Copilot supports a wide range of merchant payment operations and responds to early signs of issues with tailored recommendations. Integrated into the Antom Merchant Portal, Antom Copilot now provides enhanced automation and tailored assistance based on learnings from real-world cases, to help merchants handle payment complexity more efficiently. Main features include: Agentic support for entire payment lifecycle, from onboarding and integration, to dispute handling, risk control and payment success rate operation; Domain-trained intelligence functions like a virtual team of payment experts to manage traditionally resource-intensive
Samsung Bioepis Announces Launch of Denosumab Biosimilars, OBODENCE™ and XBRYK™, in Europe1.12.2025 08:00:00 EET | Press release
Samsung Bioepis Co., Ltd. today announced the launch of OBODENCE™ (60 mg pre-filled syringe) and XBRYK™ (120 mg vial), denosumab biosimilars referencing Prolia and Xgeva. The products will be commercially available in Europe in December 2025 and January 2026, respectively. “We are very thrilled to launch OBODENCE and XBRYK through our direct sales efforts. Osteoporosis remains a major challenge in Europe due to limited treatment options and affordability challenges. And bone-related events resulting from bone metastases significantly impact a patient's quality of life, leading to death if not treated fast enough. Our biosimilars aim to improve access, enable timely care, and ease the financial burden on healthcare systems.”, said Linda Choi MacDonald, Executive Vice President and Global Head of Commercial Division at Samsung Bioepis. “With our proven track records, we’re confident that OBODENCE and XBRYK will deliver meaningful impact on patients and their communities.” OBODENCE, refer
UAE announces Google Gemini Is Now the Most Culturally Accurate AI for Arabs28.11.2025 23:31:00 EET | Press release
The UAE’s Artificial Intelligence, Digital Economy, and Remote Work Applications Office announced that Google Gemini has ranked first in the “AI in the Ring” Index, the world’s first benchmark designed to evaluate how effectively AI language models reflect Emirati culture, dialects, traditions, and national values through a challenge centered on cultural intelligence within the UAE context. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251128785463/en/ UAE announces Google Gemini Is Now the Most Culturally Accurate AI for Arabs (Photo: AETOSWire) Gemini earned the top ranking following a review of over 400 questions across 7 cultural dimensions and 5,200 generated responses from 11 major language models. A Committee of Emirati experts evaluated the outputs to identify which models demonstrated the strongest cultural understanding. Following Gemini 2.5 Pro, the list of the top five high-performing models included: ChatGPT (O
GE HealthCare announces CE Mark for the Omni 128cm total body PET/CT system28.11.2025 13:00:00 EET | Press release
GE HealthCare today announced CE Mark for its next-generation Omni 128cm total body positron emission tomography / computed tomography (PET/CT) system,i a major milestone in its mission to advance precision care. Designed to advance cancer diagnosis, staging, therapeutic planning and treatment response monitoring, this innovative system represents a leap forward in molecular imaging capabilities and clinical efficiency. As global cancer rates continue to rise – projected to increase 77 percent by 2050ii – the need for advanced imaging solutions has never been greater. The growing prevalence of cancer and emergence of investigational immunotherapies and targeted treatments have accelerated the demand for whole-body PET/CT imaging. GE HealthCare’s new technology is built to meet this need, supporting theranostics and enabling clinicians to visualize, diagnose and monitor disease with impressive precision and speed. “Our commitment to precision health is rooted in innovation that also aim
King Abdulaziz Foundation Organizes the First Edition of the Forum on the “History of Hajj and the Two Holy Mosques” in Jeddah28.11.2025 11:53:00 EET | Press release
King Abdulaziz Foundation (Darah) held the first edition of the Forum on the “History of Hajj and the Two Holy Mosques”, convened as part of the program of the “Hajj Conference and Exhibition 2025” at the Super Dome Hall in Jeddah, in cooperation with the Ministry of Hajj and Umrah and the Guests of God Service Program, during the period from 9–12 November 2025. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251128600368/en/ King Abdulaziz Foundation Organizes the First Edition of the Forum on the “History of Hajj and the Two Holy Mosques” in Jeddah (Photo: AETOSWire) The forum’s activities were inaugurated following the announcement by His Royal Highness Prince Faisal bin Salman bin Abdulaziz Al Saud, Special Advisor to the Custodian of the Two Holy Mosques and Chairman of the Board of Directors of the King Abdulaziz Foundation, who declared the launch of the forum during the opening ceremony of the “Hajj Conference and Exh
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
