Day[0]

Static Analysis, LLMs, and In-The-Wild Exploit Chains

Nov 11, 2024
This discussion dives into the innovative use of CodeQL for uncovering hidden vulnerabilities, highlighting its customization benefits and the new platform QueryX. Large Language Models are showcased for their role in identifying SQLite vulnerabilities within real-world code. Insights from Google’s Threat Analysis Group on in-the-wild exploit chains reveal attackers' methods. The conversation also touches on emerging USB vulnerabilities and the evolving landscape of cybersecurity research and vulnerability documentation.
Ask episode
Chapters
Transcript
Episode notes