Business Wire

ShiftLeft to Present at No Hat Conference 2021

17.11.2021 11:00:00 EET | Business Wire | Press release

Share

ShiftLeft, Inc., an innovator in automated application security testing, today announced that its Chief Scientist, Fabian Yamaguchi, and Security Research Engineer, Claudiu-Vlad Ursache, will give a presentation focused on Ghidra2cpg at the No Hat Conference in Bergamo, Italy on November 20, 2021. The No Hat 2021 is a security conference organized to bring together specialists, professionals and hobbyists operating in the field of computer security and privacy.

Event Details:

Who: Fabian Yamaguchi, Chief Scientist and Claudiu-Vlad Ursache, Security Research Engineer, ShiftLeft
What: Virtual Session: Presentation on Ghidra2cpg: From graph queries to vulnerabilities in binary code
When: Saturday, November 20, 2021, 11:15am – 12:00pm CET
Where: Centro Congressi Giovanni XXIII - Bergamo, Italy

For more information, visit: https://www.nohat.it/program

Session Abstract - Ghidra2cpg: From graph queries to vulnerabilities in binary code

Uncovering bugs in source code is hard enough as it is, but when all you have is a binary, the importance of tooling becomes undeniable. Disassemblers such as IDA Pro, Ghidra, BinaryNinja or Radare2 provide a strong foundation for an investigation but are designed primarily to assist in what remains a manual investigation. This leaves room for partial automations that make the discovery process less painful.

Fabian and Claudiu were looking to design a search tool for binary code that allows them to uncover instances of programming patterns linked to vulnerabilities - at scale and for multiple major instruction sets. In this talk, they will present ghidra2cpg, an extension for the open-source code mining platform Joern that enables it to process binary code. Together, Joern and ghidra2cpg enable you to quickly uncover the attack surface, search for variants of known vulnerabilities, and gather information interactively using a query language.

In this session they will show how to write queries for the system that describe bugs in source code and introduce corresponding queries for binary code, highlighting what's harder and what is easier to describe when looking at the machine code directly. They will also be looking at modern consumer-grade router firmware and may drop a zero-day or two in the process.

About Fabian Yamaguchi

Fabian is Chief Scientist at ShiftLeft Inc and an Associate Professor Extraordinary at Stellenbosch University. He has over 15 years of experience in the security domain, where he has worked as a security consultant and researcher, focusing on manual and automated vulnerability discovery. Throughout his work, he has identified previously unknown vulnerabilities in popular system components and applications such as the Microsoft Windows kernel, the Linux kernel, the Squid proxy server, and the VLC media player. He has presented his findings and techniques at both major industry conferences such as BlackHat USA, DefCon, First, and CCC, and renowned academic security conferences such as ACSAC, Security and Privacy, and CCS. He holds a master’s degree in computer engineering from Technical University Berlin, as well as a PhD in computer science from the University of Goettingen.

About Claudiu-Vlad Ursache

Claudiu-Vlad Ursache is a Security Research Engineer at ShiftLeft, having recently entered cybersecurity after a decade of writing software. In his day-to-day job he builds static analysis tools and his current research focuses on IoT firmware.

About ShiftLeft

ShiftLeft enables software developers and application security teams to radically reduce the attackability of their applications by providing near-instantaneous security feedback on software code during every pull request. By analyzing application context and data flows in near real-time with industry leading accuracy, ShiftLeft empowers developers and appsec team to find and fix the most serious vulnerabilities faster. Using its patented graph analysis that combines code attributes and analyzes actual attack paths based on real application architecture, ShiftLeft’s platform scans for attack context and pathways typical of modern applications, across APIs, OSS, internal microservices and first-party business logic code, and then provides detailed guidance on risk remediation within existing development workflows and tooling. ShiftLeft CORE, a unified code security platform, combines the company’s flagship NextGen Static Analysis (NG SAST), Intelligent Software Composition Analysis (SCA), and contextual security training through ShiftLeft Educate to provide developers and application security teams the fastest, most accurate, most relevant, and easiest to use automated application security and code analysis platform.

Backed by Bain Capital Ventures, Mayfield, Thomvest Ventures, and SineWave Ventures, ShiftLeft is based in Santa Clara, CA. To learn how ShiftLeft keeps AppSec in sync with the rapid pace of DevOps, see https://www.shiftleft.io/.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

Contact information

PR:
Corinna Krueger
ShiftLeft
ckrueger@shiftleft.io

About Business Wire

For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

C.H. Robinson Launches World's First AI Technology That Continually Assesses, Improves and Operates Global Supply Chains3.6.2026 19:00:00 EEST | Press release

As the global leader in Lean AI supply chains, C.H. Robinson has built the first AI technology designed to both operate a shipper’s global supply chain and also continuously assess and improve its performance. Now serving the company’s 4PL Managed Solutions customers, a new Lean AI Engineer works in concert with the Lean AI Planner introduced last year to create one connected system that uniquely enhances a supply chain as it runs. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260520874794/en/ The Lean AI Engineer can assess an entire supply chain in 25 to 30 minutes and determine improvements before performance is impacted – compared to supply chain assessments that typically take up to four weeks and look backward at what has happened instead of what should happen. While the Lean AI Engineer delivers intel, the Lean AI Planner manages shipments through hundreds of interconnected AI agents and in turn feeds more data back

Leading Global Brain Science Conference OHBM 2028 to Be Held in Yokohama3.6.2026 18:00:00 EEST | Press release

Yokohama has won the bid to host the 2028 Annual Meeting of the Organization for Human Brain Mapping (OHBM 2028), one of the world’s premier international conferences in brain science, further elevating the city’s presence as a global hub for international conventions and academic exchange. The meeting will take place at PACIFICO Yokohama from June 18–22 and will mark only the second time the meeting has been held in Japan. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260603787692/en/ YOKOHAMA JAPAN'S FIRST PORT OF CALL OHBM is a leading international academic society in the fields of brain imaging, neuroscience, and neurological-disease research. Its annual meeting attracts around 3,000 researchers, healthcare professionals, and industry representatives from around the world. OHBM 2028 will be organized in collaboration with the Japan Human Brain Mapping Society (JHBM, President: Yoshikazu Ugawa and Tetsuya Matsuda). The

Almarai Launches the 2026 Cycle of the World’s Largest Award for Food Security Research in Dryland Regions3.6.2026 17:31:00 EEST | Press release

The 2026 cycle of the Almarai Prize, international track of the Almarai Prize for Scientific Creativity, has officially opened, calling on leading research institutions, distinguished scientists, and global experts to nominate pioneering research that advances food security in the world’s driest regions. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260603753914/en/ Almarai Launches the 2026 Cycle of the World’s Largest Award for Food Security Research in Dryland Regions (Photo: AETOSWire) The prize reflects Saudi Arabia’s expanding commitment to scientific innovation and to advancing solutions that tackle food security challenges in the world’s dryland regions. Almarai - a regional leader in food and agriculture - has long invested in scientific progress, sustainable farming, and long‑term food‑system resilience. As one of the world’s largest vertically integrated food companies, Almarai continues to place research and inn

Stabilizing Grids and Cutting Costs in Half: Europe Is Banking on Grid-Relevant Storage Systems3.6.2026 16:50:00 EEST | Press release

The European battery market is scaling up at record speed: According to the latest Solar+ Report from SolarPower Europe, at the end of 2025, the installed storage fleet in the EU had reached a total capacity of 40 gigawatts (GW) and a storage capacity of 77 gigawatt hours (GWh). This is an increase of over 45 percent compared to the previous year. By 2030, the study’s Solar+ scenario forecasts that capacity will quadruple to 171 GW, while storage capacity will increase eightfold to 598 GWh. As growing solar and wind capacities place increasing demands on European grids, storage systems will need to shift electricity over many hours. As a result, the average storage duration will go up from 1.9 to 3.5 hours. This represents a technological leap that underscores the need to establish more grid-relevant storage systems. Taking place in Munich from June 23–25, ees Europe will showcase how the industry is meeting this enormous demand. As Europe’s largest exhibition for batteries and energy

Onimusha: Way of the Sword Set to Release on September 25, 2026!3.6.2026 16:00:00 EEST | Press release

Capcom Co., Ltd. (TOKYO:9697) today announced that Onimusha: Way of the Sword, the latest title in the Onimusha series, is scheduled for release on September 25, 2026. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260603903549/en/ Onimusha: Way of the Sword key art Onimusha: Way of the Sword, which marks the first new title in the series in over 20 years, is a Japanese-inspired dark fantasy game that features Miyamoto Musashi as the protagonist and is set in an Edo-era Kyoto that has been twisted by malevolent clouds of Malice. Capcom is developing the title with the aim of appealing to a wide range of players through its exhilarating sword-based action and highly-unique characters. Ahead of launch, the company released a playable demo today*, June 3, 2026, titled Onimusha: Way of the Sword DEMO, to give players an opportunity to enjoy the appeal of the game as early as possible. In this demo, players can experience a varie

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye