Business Wire

ShiftLeft to Present at No Hat Conference 2021

17.11.2021 11:00:00 EET | Business Wire | Press release

Share

ShiftLeft, Inc., an innovator in automated application security testing, today announced that its Chief Scientist, Fabian Yamaguchi, and Security Research Engineer, Claudiu-Vlad Ursache, will give a presentation focused on Ghidra2cpg at the No Hat Conference in Bergamo, Italy on November 20, 2021. The No Hat 2021 is a security conference organized to bring together specialists, professionals and hobbyists operating in the field of computer security and privacy.

Event Details:

Who: Fabian Yamaguchi, Chief Scientist and Claudiu-Vlad Ursache, Security Research Engineer, ShiftLeft
What: Virtual Session: Presentation on Ghidra2cpg: From graph queries to vulnerabilities in binary code
When: Saturday, November 20, 2021, 11:15am – 12:00pm CET
Where: Centro Congressi Giovanni XXIII - Bergamo, Italy

For more information, visit: https://www.nohat.it/program

Session Abstract - Ghidra2cpg: From graph queries to vulnerabilities in binary code

Uncovering bugs in source code is hard enough as it is, but when all you have is a binary, the importance of tooling becomes undeniable. Disassemblers such as IDA Pro, Ghidra, BinaryNinja or Radare2 provide a strong foundation for an investigation but are designed primarily to assist in what remains a manual investigation. This leaves room for partial automations that make the discovery process less painful.

Fabian and Claudiu were looking to design a search tool for binary code that allows them to uncover instances of programming patterns linked to vulnerabilities - at scale and for multiple major instruction sets. In this talk, they will present ghidra2cpg, an extension for the open-source code mining platform Joern that enables it to process binary code. Together, Joern and ghidra2cpg enable you to quickly uncover the attack surface, search for variants of known vulnerabilities, and gather information interactively using a query language.

In this session they will show how to write queries for the system that describe bugs in source code and introduce corresponding queries for binary code, highlighting what's harder and what is easier to describe when looking at the machine code directly. They will also be looking at modern consumer-grade router firmware and may drop a zero-day or two in the process.

About Fabian Yamaguchi

Fabian is Chief Scientist at ShiftLeft Inc and an Associate Professor Extraordinary at Stellenbosch University. He has over 15 years of experience in the security domain, where he has worked as a security consultant and researcher, focusing on manual and automated vulnerability discovery. Throughout his work, he has identified previously unknown vulnerabilities in popular system components and applications such as the Microsoft Windows kernel, the Linux kernel, the Squid proxy server, and the VLC media player. He has presented his findings and techniques at both major industry conferences such as BlackHat USA, DefCon, First, and CCC, and renowned academic security conferences such as ACSAC, Security and Privacy, and CCS. He holds a master’s degree in computer engineering from Technical University Berlin, as well as a PhD in computer science from the University of Goettingen.

About Claudiu-Vlad Ursache

Claudiu-Vlad Ursache is a Security Research Engineer at ShiftLeft, having recently entered cybersecurity after a decade of writing software. In his day-to-day job he builds static analysis tools and his current research focuses on IoT firmware.

About ShiftLeft

ShiftLeft enables software developers and application security teams to radically reduce the attackability of their applications by providing near-instantaneous security feedback on software code during every pull request. By analyzing application context and data flows in near real-time with industry leading accuracy, ShiftLeft empowers developers and appsec team to find and fix the most serious vulnerabilities faster. Using its patented graph analysis that combines code attributes and analyzes actual attack paths based on real application architecture, ShiftLeft’s platform scans for attack context and pathways typical of modern applications, across APIs, OSS, internal microservices and first-party business logic code, and then provides detailed guidance on risk remediation within existing development workflows and tooling. ShiftLeft CORE, a unified code security platform, combines the company’s flagship NextGen Static Analysis (NG SAST), Intelligent Software Composition Analysis (SCA), and contextual security training through ShiftLeft Educate to provide developers and application security teams the fastest, most accurate, most relevant, and easiest to use automated application security and code analysis platform.

Backed by Bain Capital Ventures, Mayfield, Thomvest Ventures, and SineWave Ventures, ShiftLeft is based in Santa Clara, CA. To learn how ShiftLeft keeps AppSec in sync with the rapid pace of DevOps, see https://www.shiftleft.io/.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

Contact information

PR:
Corinna Krueger
ShiftLeft
ckrueger@shiftleft.io

About Business Wire

For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

HKTDC to Host World’s Largest One-Stop Jewellery Marketplace9.2.2026 12:37:00 EET | Press release

Organised by the Hong Kong Trade Development Council (HKTDC), the world’s largest one‑stop jewellery marketplace will return in early March under its proven “Two Shows, Two Venues” format. The 12th Hong Kong International Diamond, Gem & Pearl Show will take place from 2 to 6 March at AsiaWorld‑Expo, featuring a wide range of jewellery raw materials. Also, the 42nd Hong Kong International Jewellery Show will be held from 4 to 8 March at the Hong Kong Convention and Exhibition Centre, showcasing finished jewellery pieces. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260207153040/en/ Hong Kong International Jewellery Show and Hong Kong International Diamond, Gem & Pearl Show Jenny Koo, Deputy Executive Director of the HKTDC, said: “This year’s twin jewellery shows bring together some 4,000 exhibitors from over 40 countries and regions, with nearly 70% coming from outside Hong Kong. The HKTDC presents the world’s largest one-s

FlexTrade Integrates CME Group’s FX Spot+ and EBS Market Offerings for Enhanced FX Trading9.2.2026 12:30:00 EET | Press release

FlexTrade Systems(@FlexTrade), a global leader in multi-asset execution and order management systems, today announced an integration with CME Group’s EBS Market central limit order book (CLOB) and its FX Spot+ platform.The move is designed to diversify and deepen the sources of actionable liquidity available to FlexTrade’s FlexFX users through an integration into CME Group's substantial liquidity pools for spots via FX Spot+. Providing firm, anonymous liquidity and no last-look pricing, EBS Market is a venue for both large market participants in search of FX liquidity in an all-to-all CLOB, and for market-making banks hedging FX risk. FX Spot+ further enhances spot liquidity with Futures liquidity from CME Group. This partnership is integral in helping firms further expand FX liquidity and take advantage of global opportunity. Mutual clients of FlexTrade and CME Group can integrate FX Spot+ and EBS Market liquidity into their existing FlexFX workflows, accelerating time to market and r

Clearwater Analytics Debuts Transparent Risk Platform for Power and Gas Markets at E-world 20269.2.2026 10:00:00 EET | Press release

At E-world Energy & Water 2026, Clearwater Analytics (NYSE: CWAN) will debut CWAN Power and Gas, new risk management capabilities within Beacon by CWAN designed to end the industry’s reliance on black-box systems. With transparent methodologies and source-code visibility, the platform lets trading teams validate and customize calculations for complex power and gas instruments in real time. Visit Booth #5A118 in Hall 5 for live demonstrations. Renewables growth, liquefied natural gas flows, and shifting macroeconomic conditions are reshaping power markets and increasing both volatility and opportunity. Yet many trading firms remain constrained by legacy risk platforms that limit model visibility, customization, and speed-to-market. CWAN Power and Gas removes those constraints by making every calculation transparent, configurable, and auditable in real time—supporting complex instruments such as structured power derivatives and evolving trading strategies. “The energy transition is creat

PANECO to Exhibit at EuroShop 2026 -- Seeking Global Sales Partners for Sustainable Materials Made from Textile Waste --9.2.2026 09:00:00 EET | Press release

PANECO®, a textile circularity and sustainable materials platform developed by WORKSTUDIO Co., Ltd. (Tokyo, Japan), will exhibit at EuroShop 2026, held in Düsseldorf, Germany. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260203145499/en/ Textile Recycling Board | PANECO Visitors to EuroShop are actively searching for sustainable materials that can be implemented in commercial spaces and furniture. Across Europe and globally, demand for the practical implementation of sustainable materials is rapidly increasing. In this environment, materials are expected to be not only environmentally responsible, but also scalable, reliable, and commercially viable. In response to this market demand, PANECO® transforms textile waste into high-quality recycled boards, offering sustainable solutions for commercial spaces and furniture. These materials are designed for real-world applications such as retail interiors, furniture, fixtures, an

Tigo Energy EI Residential Solar-plus-Storage Solution Certified with Romanian Grid Operators9.2.2026 07:00:00 EET | Press release

Tigo Energy, Inc. (NASDAQ: “TYGO”) (“Tigo” or “Company”), a leading provider of intelligent solar and energy software solutions, today announced the successful certification of the Tigo EI Residential solar-plus-storage solution with Romanian distribution system operators, further expanding market reach of Tigo products across Europe. Following the successful completion of their respective grid-compliance and certification procedures with Distribuție Energie Electrică Romania (DEER), Distribuție Oltenia, and Rețele Electrice, single-phase and three-phase configurations of the EI Residential solution are now fully listed and approved for use in the Romanian market. With 2026 expected to be another strong year for solar growth nationally, the Tigo EI Residential system becomes an important addition to the list of options for installers deploying advanced solar-plus-storage systems in Romania. In line with its National Energy and Climate Plan, Romania added approximately 2.2GW of new sola

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye