

Static Analysis, LLMs, and In-The-Wild Exploit Chains
Nov 11, 2024
This discussion dives into the innovative use of CodeQL for uncovering hidden vulnerabilities, highlighting its customization benefits and the new platform QueryX. Large Language Models are showcased for their role in identifying SQLite vulnerabilities within real-world code. Insights from Google’s Threat Analysis Group on in-the-wild exploit chains reveal attackers' methods. The conversation also touches on emerging USB vulnerabilities and the evolving landscape of cybersecurity research and vulnerability documentation.
Chapters
Transcript
Episode notes
1 2 3 4 5 6 7 8
Intro
00:00 • 3min
Enhancing Security with CodeQL
03:22 • 8min
Exploring CodeQL: Queries and Vulnerabilities
11:13 • 16min
Unlocking Security: LLMs in Cyber Defense
27:36 • 22min
Exploit Chains and Cybersecurity Evolution
50:00 • 17min
Exposing USB Vulnerabilities in Hardware Security
01:07:08 • 4min
Exploring Recent Academic Insights from Usenik's Woot Conference
01:11:36 • 6min
Navigating Vulnerability Research and Emerging CVE Guidelines
01:17:20 • 5min