BlogPartners

Webinar

The Dependency Mirage: Hidden Vulnerabilities in Compiled Binaries

Watch as Craig Heffner, Senior Staff Engineer, demonstrates how to identify statically linked and vendored code, validate suspicious scanner findings, and engage vendors with verifiable evidence of risk. Learn why binaries don’t lie — and why Binary Composition Analysis is essential for uncovering hidden vulnerabilities your SBOMs miss.

Speakers

Craig Heffner

Senior Staff Engineer

Key Takeaways

  • logo-star

    SBOMs and scanners often reflect intent, not production reality:

    The session argues that manifest-based scanning misses hidden dependencies and build-time choices, creating vulnerabilities that traditional tools simply don’t see.

  • Binary Composition Analysis shows what’s actually compiled:

    By analysing binaries directly, BCA exposes statically linked and vendored components—turning “we think it’s there” into verifiable evidence of what’s running.

  • Real examples prove it’s a systemic blind spot:

    Cases like OpenSSL 3.0.0 statically linked inside Python modules and zlib 1.2.8 embedded in rsync despite manifests listing 1.3.1 demonstrate why “binaries don’t lie,” and how teams can validate findings and press vendors with proof.

Stay up to date with the news

Sign up to get our free insights delivered to your inbox.