
slides
CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU
dynamic-code-analysiseducationpapers-research+2

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

Clickbait. The CVE is AI slop.

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.