Sylwia Budzynska
Sylwia ‘BlazingWind’ Budzynska is a security researcher at GitHub Security Lab, where she hunts for vulnerabilities in open source software, specializing in Python and at-scale static analysis tooling. She has found 80+ CVEs and spoken at a number of conferences and events, including The Hack Summit Warsaw, OrangeCon Amsterdam, CoderGirls Aarhus, 0-day Aarhus and others.
Most of her research is available on https://github.blog/author/sylwiabudzynska/ and most of her advisories on https://securitylab.github.com/advisories/.
In free time, Sylwia enjoys dance classes, reading fantasy, hiking and gaming.
Sessions
This tutorial will introduce fundamentals of security research and CodeQL when looking for security vulnerabilities in software. We'll share how to look for vulnerabilities in code and how to use static analysis to help us find sources, sinks and vulnerabilities.
Using an example of a vulnerability in an open source project that the speaker has found, CVE-2024-32022, we will walk through how we could detect it manually by reading code, learn how to write CodeQL, and by the end write a CodeQL query to find this vulnerability and its variants.
To workshop attendees:
Workshop repository is available at: https://gh.io/europython-codeql
To do before the workshop: install VS Code and set up the workshop repository following the instructions: https://github.com/sylwia-budzynska/codeql-workshop/?tab=readme-ov-file#option-a-local-installation. It should take 5-10 minutes.
If you can’t/don’t want to set up VS Code, you can create a codespace of the workshop repository which automatically downloads and installs everything we need for running CodeQL by following these instructions: https://github.com/sylwia-budzynska/codeql-workshop/?tab=readme-ov-file#option-b-github-codespace
During the workshop I will set up the codespace and do all the exercises together with you. The workshop materials have a lot of reference material, cheatsheets, etc. Don’t worry about it for now. It’s there for you to go back to during the hands-on session in case something wasn’t fully clear.
This tutorial will introduce fundamentals of security research and CodeQL when looking for security vulnerabilities in software. We'll share how to look for vulnerabilities in code and how to use static analysis to help us find sources, sinks and vulnerabilities.
Using an example of a vulnerability in an open source project that the speaker has found, CVE-2024-32022, we will walk through how we could detect it manually by reading code, learn how to write CodeQL, and by the end write a CodeQL query to find this vulnerability and its variants.
To workshop attendees:
Workshop repository is available at: https://gh.io/europython-codeql
To do before the workshop: install VS Code and set up the workshop repository following the instructions: https://github.com/sylwia-budzynska/codeql-workshop/?tab=readme-ov-file#option-a-local-installation. It should take 5-10 minutes.
If you can’t/don’t want to set up VS Code, you can create a codespace of the workshop repository which automatically downloads and installs everything we need for running CodeQL by following these instructions: https://github.com/sylwia-budzynska/codeql-workshop/?tab=readme-ov-file#option-b-github-codespace
During the workshop I will set up the codespace and do all the exercises together with you. The workshop materials have a lot of reference material, cheatsheets, etc. Don’t worry about it for now. It’s there for you to go back to during the hands-on session in case something wasn’t fully clear.
This panel brings together experts from different corners of the field to talk about how generative AI is changing cybersecurity and the tricky challenges that come with it. Not only will we explore the technical aspects, but also the ethical considerations our society must have with in this rapidly evolving landscape.
We're not treating this as just a technical conversation. Generative AI in cybersecurity touches code, strategy, and ethics all at once, and we want to dig into all three. By the end of the panel, you should walk away with a clearer sense of the real risks at the language and ecosystem level, some practical lessons from teams working security operations day to day, and a more grounded take on the ethical questions this technology raises.