Explore tweets tagged as #CodeQL
@noperator
Caleb Gross
4 months
A new tool: Slice 🔪 With the help of build-free CodeQL and Tree-Sitter, Slice can help GPT-5 can reliably reproduce discovery of CVE-2025-37778: use-after-free vulnerability in the Linux kernel! https://t.co/J2na8iX4hv
4
52
169
@dcuthbert
Daniel Cuthbert
5 days
First up, one of my highlighted talks and no surprise why: codeql baby! Simcha built an open-source tool that fuses CodeQL with an LLM-driven agent. Mo
16
1
8
@hkashfi
Hamid Kashfi
4 days
The one talk from BH EU I started reading about right away: Flaw And Order: Finding The Needle In The Haystack Of CodeQL Using LLMs CyberArk’s blog about it: https://t.co/uquVQs0fJ2 Slides: https://t.co/GDlinjldsf Vulnhalla release: https://t.co/y7hMEQrqHm
2
4
27
@raysan5
Ray
19 days
NEWS! #raylib is going through a security audit in the following months by Radically Open Security @ROSecurity! 🚀 First time going through a professional security audit (beside the CodeQL static analysis engine from GitHub). Let's see how it goes! Really exciting! 😄
9
15
382
@RoxsRoss
RoxsRoss
2 months
🔥 ¿Tu código es realmente seguro o solo confías en los tests? El verdadero poder de un pipeline DevSecOps está en combinar las 3 miradas 👇 📦 SCA: analiza dependencias (Trivy, Snyk, Grype) 💻 SAST: revisa tu código (Semgrep, SonarQube, CodeQL) 🌐 DAST: prueba tu app en
2
11
56
@mqst_
Muqsit 𝕏
2 months
Taming 2,500 compiler warnings with CodeQL, an OpenVPN2 case study Blog: https://t.co/zkWR1of98K Author: Paweł Płatek, Jay Little (@trailofbits)
0
1
12
@dcuthbert
Daniel Cuthbert
13 days
aaaah yiss... I'm chuffed the stuff I was doing with the GitHub/CodeQL crew on datapath visualisation, made it into this codebase.
@gadievron
Gadi Evron
13 days
Introducing RAPTOR, an Autonomous Offensive/Defensive Research Framework based on Anthropic's Claude Code, written by @dcuthbert, @halvarflake, @mbrg0, and myself. Let's rock. Get it from GitHub, here:
0
3
20
@_atorralba
Tony Torralba
2 years
Happy to share that @pwntester and I will be presenting our talk "Finding vulnerabilities at scale in Jenkins plugins with CodeQL" at @BarcelonaBsides, happening on May 29-30. Join us to learn about CodeQL, vulnerability research at scale, and the Jenkins plugin ecosystem!
0
6
26
@dcuthbert
Daniel Cuthbert
2 months
Oh so yous wanna run codeql huh and do some crypto shit? never seen sys stats that look like a phone number, but ok
2
0
5
@linkersec
Linux Kernel Security
27 days
Slice: SAST + LLM Interprocedural Context Extractor Amazing article by @noperator about combining the use of CodeQL and LLMs to reliably rediscover CVE-2025-37899 — a remotely-triggerable vulnerability in the ksmbd module. https://t.co/jnC9xZlkNw
1
13
35
@0xor0ne
0xor0ne
1 month
CodeQL series by Sylwia Budzynska (@BlazingWindSec) Static analysis fundamentals: https://t.co/4lGZyXjuQG Getting started: https://t.co/3NNA3aGjiR Security research: https://t.co/zOL3XOJJq4 Gradio framework case study: https://t.co/ip8GFPzO0c Debugging queries:
0
28
137
@IceSolst
solst/ICE of Astarte
2 months
Great post by @noperator: built a sast tool that uses codeql (which can now scan c++ without compiling) and tree sitter, and triage with an LLM to find vulns with a low false positive rate
3
6
47
@samlakig
yule sam
2 months
next 4 days, my special interest will be control flow analysis. prof told me to read the nice paper by van Horn et al. for the more FP side of CFA, also gonna read up more on codeql and how static analyers use these techniques
2
0
26
@hasamba
Yaniv Radunsky
9 days
RAPTOR: autonomous offensive/defensive research framework combining Semgrep, CodeQL, AFL, radare2 and rr for scanning, fuzzing, crash analysis and PoC/patch generation. Open-source research tool. #tool #fuzzing #staticanalysis https://t.co/6PraK5honc
1
26
98
@zeyu1337
zayne (zeyu) zhang
9 months
My slides from today's talk about Static Program Analysis. I go into how data flow analysis (like taint propagation in CodeQL) works from first principles - should be digestible with some first-year university maths knowledge https://t.co/lgvdS7BySo
0
34
160
@dcuthbert
Daniel Cuthbert
2 months
Ok now you got me excited. CodeQL into copilot
0
1
4
@nullcon
NULLCON
24 days
At #NullconGoa2026, get hands-on with the tools and techniques experts use to uncover vulnerabilities others miss - led by security veterans Markus Vervier & Eric Sesterhenn. Know More: https://t.co/f0TSkgBlf6 #AppSec #SecurityTraining #CodeQL #Fuzzing #Clang
0
0
1
@07finder
Finder
9 days
CVE-2025-66624 I discovered this vulnerability through CodeQL
@CVEnew
CVE
9 days
CVE-2025-66624 BACnet Protocol Stack library provides a BACnet application layer, network layer and media access (MAC) layer communications services. Prior to 1.5.0.rc2, The npdu_is…
3
1
26
@payloadartist
payloadartist
8 months
Another day, another secret in an artifact leads to potential doom. @Praetorian_Labs found a token valid for only 1 SECOND in a @GitHub CodeQL debug artifact. They raced it, got write perms, and could've poisoned the v3 tag used by HUNDREDS OF THOUSANDS of repos. 🔗👇
2
11
72