Webinar
The Dependency Mirage: Hidden Vulnerabilities in Compiled Binaries
Watch as Craig Heffner, Senior Staff Engineer, demonstrates how to identify statically linked and vendored code, validate suspicious scanner findings, and engage vendors with verifiable evidence of risk. Learn why binaries don’t lie — and why Binary Composition Analysis is essential for uncovering hidden vulnerabilities your SBOMs miss.
Key Takeaways
SBOMs and scanners often reflect intent, not production reality:
The session argues that manifest-based scanning misses hidden dependencies and build-time choices, creating vulnerabilities that traditional tools simply don’t see.
Binary Composition Analysis shows what’s actually compiled:
By analysing binaries directly, BCA exposes statically linked and vendored components—turning “we think it’s there” into verifiable evidence of what’s running.
Real examples prove it’s a systemic blind spot:
Cases like OpenSSL 3.0.0 statically linked inside Python modules and zlib 1.2.8 embedded in rsync despite manifests listing 1.3.1 demonstrate why “binaries don’t lie,” and how teams can validate findings and press vendors with proof.
Stay up to date with the news
Sign up to get our free insights delivered to your inbox.
You might also like
Learn how we helped the customers to reach the next level





