The Dependency Mirage: Hidden Vulnerabilities in Your Compiled Binaries @FIRSTdotorg
The Dependency Mirage: Hidden Vulnerabilities in Your Compiled Binaries  @FIRSTdotorg
Uploaded May 2026 | Updated September 2026, 2 hours ago
Craig Heffner (NetRise, US), Peter Eacmen (Netrise)

Your application security scanners are lying to you. Manifest files show what developers intended to ship, but compiled binaries reveal a harsher truth: hidden, vulnerable dependencies that never show up in SBOMs. This session uses real-world case studies to expose the gap and show how Binary Composition Analysis uncovers the vulnerabilities your tools miss.

---

Peter Eacmen, Senior Staff Engineer @ Netrise DEFCON Black Badge winner, member of the sk3wl 0f r00t Capture the Flag Team. A lifelong hacker, Peter began his career as a Global Network Vulnerability Analyst at the NSA where he focused on identifying and exploiting vulnerabilities in embedded devices to protect national security. He co-founded Tactical Network Solutions with Terry, where he led the engineering teams and the development of technology that became ReFirm Lab's Centrifuge Platform®. Peter co-founded ReFirm Labs in 2017. Peter has a BS in Computer Science and Computational Mathematics from Rensselaer Polytechnic Institute, and an MS in Computer Science and Discrete Mathematics from the Naval Postgraduate School.

Craig Heffner is a Senior Staff Engineer at NetRise and the creator of Binwalk, the widely used open-source firmware analysis and extraction tool. With 20+ years of experience analyzing embedded and wireless systems, he's presented at major security conferences including Black Hat and DEF CON and has previously worked across government and industry, including the NSA and Microsoft.
The Dependency Mirage: Hidden Vulnerabilities in Your Compiled BinariesTransforming Vulnerability Management with Advanced Dependency Knowledge GraphsA Researcher Centric Approach to Coordinated Vulnerability DisclosureHow to Answer “What’s Affected?” in Open SourceSysmon Deep Dive: Real Detection Scenarios You Can ReproduceThe PR3TACK Initiative: Building the World’s First Preemptive Tactics & Countermeasures KnowledgebasGuardians of the HypervisorBest Practices for Data Privacy Breach Response: Lessons Learned from Social Media Case StudiesThe Ontology for SOC Creation Assistance and Replication (OSCAR)Panel: Peak Performance Under Pressure: Building Cross-Functional Resilience in Incident ResponseYou Need Some Neurosparkle In Your SOCNavigating the Threat Actor Maze: A Tool for Mapping Names, Families and Insights
FIRST |

The Dependency Mirage: Hidden Vulnerabilities in Your Compiled Binaries

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER