<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/"><channel><title>Announcements on SecMate Blog</title><link>https://blog.secmate.dev/categories/announcements/</link><description>What we find. What we share.</description><generator>Hugo</generator><language>en-us</language><managingEditor>noreply@blog.secmate.dev//blog.secmate.dev/ (SecMate Team)</managingEditor><lastBuildDate>Sat, 25 Jul 2026 09:06:44 +0000</lastBuildDate><atom:link href="https://blog.secmate.dev/categories/announcements/index.xml" rel="self" type="application/rss+xml"/><item><title>SecMate Joins the Cyber Defense Factory Program</title><link>https://blog.secmate.dev/posts/secmate-cyberdefense-factory/</link><pubDate>Mon, 09 Feb 2026 00:00:00 +0000</pubDate><dc:creator>Maxime Rossi Bellom</dc:creator><dc:creator>Ramtine Tofighi Shirazi</dc:creator><category>Announcements</category><guid>https://blog.secmate.dev/posts/secmate-cyberdefense-factory/</guid><description>SecMate integrates the Cyber Defense Factory program led by the Agence de l'innovation de défense (AID), accelerating field validation, workflow integration, and iteration on critical software security.</description><content:encoded><![CDATA[<h1 id="secmate-joins-the-cyber-defense-factory-program">SecMate joins the Cyber Defense Factory program</h1>
<div style="text-align: center;">
<img src="/images/cdf-logo.png" alt="Cyber Defense Factory logo" style="width: 100%; max-width: 400px; margin: 1.5rem auto; display: block;">
</div>
<p>SecMate is joining the <strong>Cyber Defense Factory</strong>, a program led by the <strong>French Directorate General of Armaments (<em>Direction générale de l&rsquo;armement</em>)</strong> <a href="#ref1">[1]</a>
, the <strong>French Cyber Defence Command (<em>Commandement de la cyberdéfense</em>)</strong> <a href="#ref2">[2]</a>
, and the <strong>French Defence Innovation Agency (<em>Agence de l&rsquo;innovation de défense</em>)</strong> <a href="#ref3">[3]</a>
.</p>
<p>The Cyber Defense Factory is an environment designed to foster innovation by providing access to cyber-interest data, and the ability to test solutions alongside experts and operational users from the French Ministry of Armed Forces (<em>Ministère des Armées</em>) <a href="#ref4">[4]</a>
.</p>
<p>For SecMate, this creates the conditions to run our product in a highly demanding context: real datasets, real constraints, and direct evaluation with operational users.</p>
<p>Our mission remains the same: find the vulnerabilities that matter in embedded and critical software, reduce the noise that slows teams down, and deliver actionable findings directly in the development workflow. We built SecMate from years of offensive security research, and this program reinforces our ability to apply that expertise where it counts most.</p>
<p>If you build or secure critical software (embedded, systems, components) and want to reduce vulnerability risk at scale, we would love to hear from you.</p>
<hr>
<p> </p>
<h1 id="secmate-intègre-la-cyber-defense-factory">SecMate intègre la Cyber Defense Factory</h1>
<p>SecMate intègre la <strong>Cyber Defense Factory</strong>, un programme porté par la <strong>Direction générale de l&rsquo;armement (DGA)</strong> <a href="#ref1">[1]</a>
, le <strong>Commandement de la cyberdéfense (COMCYBER)</strong> <a href="#ref2">[2]</a>
 et l&rsquo;<strong>Agence de l&rsquo;innovation de défense (AID)</strong> <a href="#ref3">[3]</a>
.</p>
<p>La Cyber Defense Factory est un programme dédié à l&rsquo;innovation en matière de cyberdéfense. Il offre un accès à des données d&rsquo;intérêt cyber, ainsi que la possibilité de tester des solutions aux côtés d&rsquo;experts et d&rsquo;opérationnels du Ministère des Armées <a href="#ref4">[4]</a>
.</p>
<p>Pour SecMate, c&rsquo;est une étape importante pour contribuer à la sécurisation de logiciels critiques, où la maîtrise du risque et la résilience opérationnelle sont clés.</p>
<p>Notre mission reste la même : détecter les vulnérabilités qui comptent dans les logiciels embarqués et critiques, réduire le bruit qui ralentit les équipes, et produire des résultats actionnables directement intégrés au flux de développement. SecMate est né de plusieurs années de recherche en sécurité offensive, et ce programme renforce notre capacité à appliquer cette expertise là où elle est la plus nécessaire.</p>
<p>Si vous développez ou sécurisez des logiciels critiques (embarqué, systèmes, composants) et souhaitez réduire le risque de vulnérabilités à grande échelle, n&rsquo;hésitez pas à nous contacter.</p>
<h2 id="références">Références</h2>
<ul>
<li>
<p><a id="ref1"></a>[1] Direction générale de l&rsquo;armement (DGA). <a href="https://www.defense.gouv.fr/dga" rel="noopener noreferrer" target="_blank">Site</a>
</p>
</li>
<li>
<p><a id="ref2"></a>[2] Commandement de la cyberdéfense (COMCYBER). <a href="https://www.defense.gouv.fr/comcyber/commandement-cyberdefense-comcyber" rel="noopener noreferrer" target="_blank">Site</a>
</p>
</li>
<li>
<p><a id="ref3"></a>[3] Agence de l&rsquo;innovation de défense (AID). <a href="https://www.defense.gouv.fr/aid" rel="noopener noreferrer" target="_blank">Site</a>
</p>
</li>
<li>
<p><a id="ref4"></a>[4] Ministère des Armées / AID. « Appel à projets – Cyber Defense Factory. » <a href="https://www.defense.gouv.fr/aid/appels-projets/clotures/appel-projets-cyber-defense-factory" rel="noopener noreferrer" target="_blank">Lien</a>
</p>
</li>
</ul>
<p><em>The SecMate Team</em></p>
]]></content:encoded><media:content url="https://blog.secmate.dev/images/og_image.jpg" medium="image"/></item><item><title>From the Attacker's Playbook to Your Pull Request</title><link>https://blog.secmate.dev/posts/hello-world/</link><pubDate>Wed, 23 Jul 2025 10:00:00 +0000</pubDate><atom:updated>2025-07-23T10:00:00+00:00</atom:updated><dc:creator>Maxime Rossi Bellom</dc:creator><dc:creator>Ramtine Tofighi Shirazi</dc:creator><category>Announcements</category><guid>https://blog.secmate.dev/posts/hello-world/</guid><description>SecMate enters beta. Founded by former Quarkslab researchers, we turn offensive security expertise into a developer-facing tool that finds exploitable vulnerabilities in complex code.</description><content:encoded><![CDATA[<h1 id="from-the-attackers-playbook-to-your-pull-request">From the Attacker&rsquo;s Playbook to Your Pull Request</h1>
<h2 id="introducing-secmate-beta-release">Introducing SecMate Beta Release</h2>
<p>Before founding SecMate, we spent most of our careers in the trenches of cybersecurity and vulnerability research, often on the attacker&rsquo;s side of the field.</p>
<p>Our offensive security approach revealed vulnerabilities in some of the world&rsquo;s most secure devices, showing us firsthand how complex systems fail. We also pioneered using machine learning for security research, developing techniques to bypass protections long before LLMs (Large Language Models) made headlines.</p>
<p>Throughout our experiences, we were consistently struck by the same reality: there’s a painful disconnection between the tools that development teams are given and the real-world security challenges they face.</p>
<p>We felt a growing sense of responsibility to help bridge this gap.</p>
<p><strong>This is why we started <a href="https://secmate.dev?utm_source=blog&amp;utm_medium=body&amp;utm_campaign=hello-world&amp;utm_content=announcements" rel="noopener noreferrer" target="_blank" data-cta-type="body_secmate" data-post-slug="hello-world" data-post-category="announcements">SecMate</a>
.</strong></p>
<h2 id="the-challenge-we-all-face">The Challenge We All Face</h2>
<p>We aim to make developers&rsquo; lives easier by focusing on real vulnerabilities and uncovering complex flaws that would otherwise remain hidden.</p>
<p>We have witnessed the productivity bottleneck that development teams face when shipping features at incredible speed while maintaining security <a href="#ref1">[1]</a>
.</p>
<p>What struck us most was the diversity of experiences. Some developers shared that they struggle to understand how security relates to their daily work. Others described feeling overwhelmed by security requirements. Security leaders told us about spending countless hours fine-tuning tools as strict settings flood teams with false positives, while relaxed configurations miss important issues. Academic studies confirm they are not alone: SAST tools detect on average only 12.7% of real-world vulnerabilities <a href="#ref2">[2]</a>
, with detection rates highly dependent on settings <a href="#ref3">[3]</a>
.</p>
<p>These valuable conversations and research findings revealed a pattern: well-intentioned security tools often create additional complexity. Teams described dealing with alert fatigue and struggling to identify which issues truly matter <a href="#ref4">[4]</a>
. This helps explain why most applications still have security flaws, even after years in production <a href="#ref5">[5]</a>
.</p>
<p>Despite the recent rise in AI-driven <em>security</em> products aimed at solving some of these challenges, the latest academic findings show that off-the-shelf LLMs struggle with the deep semantic reasoning required for security <a href="#ref6">[6]</a>
.</p>
<p>The challenge is not about assigning blame. <strong>It is about bridging the gap between what development teams need and what current tools provide.</strong></p>
<h2 id="our-approach-derived-from-field-lessons">Our Approach, Derived from Field Lessons</h2>
<p>We believe security tools should empower developers and protect end users. So, we built SecMate on the direct lessons from our research: analyzing the Samsung boot chain <a href="#ref7">[7]</a>
, finding unintended code execution paths on Google&rsquo;s Titan M <a href="#ref8">[8]</a>
,<a href="#ref9">[9]</a>
, and using Machine Learning and Ensemble Learning to remove code obfuscations <a href="#ref10">[10]</a>
, <a href="#ref11">[11]</a>
.</p>
<p>We learned that the most critical vulnerabilities are not simple syntax errors, they often are complex architectural flaws (e.g., Samsung&rsquo;s Odin protocol vulnerability <a href="#ref12">[12]</a>
). Our purpose is to design SecMate to find those specific security issues on complex codebases.</p>
<p>Moreover, recent studies have also shown that LLMs struggle to track relationships across data and control flow <a href="#ref6">[6]</a>
. Thus, relying only on prompt engineering is not enough. In some cases, they even perform no better than random guessing on realistic samples <a href="#ref13">[13]</a>
.</p>
<p>You might wonder how SecMate addresses these challenges:</p>
<ol>
<li>
<p><strong>A Deeper Code Understanding with Intermediate Representation (IR)</strong>: SecMate lifts your source code into a common IR that preserves the semantics of your code. This allows for a much richer analysis than just scanning raw text and is considered a vital way to overcome the limitations of LLMs alone <a href="#ref14">[14]</a>
.</p>
</li>
<li>
<p><strong>Analysis Guided by Research, Not Just Rules</strong>: We combine static analyses from formal methods techniques with custom rules and patterns learned directly from our offensive research. This enables SecMate to find nuanced, high-risk vulnerabilities, that other tools often miss.</p>
</li>
<li>
<p><strong>Actionable Guidance in Your Workflow</strong>: SecMate delivers clear findings directly into your pull request. Instead of just flagging a problem, it provides context and, where possible, a guided fix you can review and merge. Our goal is to make real security a productive part of the development process.</p>
</li>
</ol>
<p><strong>And this is just the beginning.</strong></p>
<h2 id="who-we-hope-to-help">Who We Hope to Help</h2>
<p>SecMate is built as a versatile security solution for any codebase. However, we are starting with a focus on the domains where our expertise runs deepest and where current tools may fall short:</p>
<ul>
<li>Embedded systems and connected devices</li>
<li>Mobile applications</li>
</ul>
<h2 id="join-us-in-building-the-solution">Join Us In Building the Solution</h2>
<p>We are looking for design partners to help us shape the future of SecMate. This is not just about trying a new product: <strong><a href="https://secmate.dev/#waitlist?utm_source=blog&amp;utm_medium=body&amp;utm_campaign=hello-world&amp;utm_content=announcements" rel="noopener noreferrer" target="_blank" data-cta-type="body_register" data-post-slug="hello-world" data-post-category="announcements">it’s an invitation to collaborate and shape security to your needs.</a>
</strong></p>
<p>Your feedback will be critical in helping us build a solution that truly solves the problems we all face, not only during development, but also for users once solutions are in production.</p>
<h2 id="acknowledgments">Acknowledgments</h2>
<p>No product is built in a vacuum, and we are incredibly grateful for the support we have received on this journey so far.</p>
<p>Our sincere thanks go to our early design partners and beta-testers who placed their trust in us and are providing invaluable feedback. Their insights are directly shaping the future of SecMate. We are particularly indebted to our technical advisor, Philippe Teuwen, whose guidance and support are critical.</p>
<p>Finally, we want to thank and acknowledge our great former colleagues at <a href="https://quarkslab.com" rel="noopener noreferrer" target="_blank">Quarkslab</a>
. It was an environment that fostered the deep technical curiosity that underpins our work, and we are grateful for the years spent learning and growing alongside such a talented team and amazing clients.</p>
<h2 id="references">References</h2>
<ul>
<li>
<p><a id="ref1"></a>[1] IT Pro. &ldquo;Developers spend 17 hours a week on security — but don&rsquo;t consider it a top priority&rdquo; <em>IT Pro Today</em>, March 28, 2025. <a href="https://www.itpro.com/security/developers-spend-17-hours-security-dont-consider-it-a-top-priority" rel="noopener noreferrer" target="_blank">Article</a>
</p>
</li>
<li>
<p><a id="ref2"></a>[2] Kaixuan Li et L. &ldquo;Comparison and Evaluation on Static Application Security Testing (SAST) Tools for Java&rdquo;. <em>ESEC/FSE 2023</em>. <a href="https://sen-chen.github.io/img_cs/pdf/fse2023-sast.pdf" rel="noopener noreferrer" target="_blank">PDF</a>
</p>
</li>
<li>
<p><a id="ref3"></a>[3] Richard A. Dubniczky et al. &ldquo;CASTLE: Benchmarking Dataset for Static Code Analyzers and LLMs towards CWE Detection&rdquo;. <a href="https://arxiv.org/pdf/2503.09433v1" rel="noopener noreferrer" target="_blank">PDF</a>
</p>
</li>
<li>
<p><a id="ref4"></a>[4] Filiz Mizrak et al. &ldquo;Exploring the impact of cybersecurity fatigue on employee productivity and mental health.&rdquo; <a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC11861440/" rel="noopener noreferrer" target="_blank">PMC</a>
</p>
</li>
<li>
<p><a id="ref5"></a>[5] Help Net Security. &ldquo;70% of apps contain at least one security flaw after 5 years in production.&rdquo; <em>Help Net Security</em>, January 13, 2023. <a href="https://www.helpnetsecurity.com/2023/01/13/apps-security-flaws-production/" rel="noopener noreferrer" target="_blank">Article</a>
</p>
</li>
<li>
<p><a id="ref6"></a>[6] Yangson Li et al. &ldquo;SV-TrustEval-C: Evaluating Structure and Semantic Reasoning in Large Language Models for Source Code Vulnerability Analysis.&rdquo; <em>IEEE S&amp;P 2025</em>. <a href="https://arxiv.org/pdf/2505.20630" rel="noopener noreferrer" target="_blank">PDF</a>
</p>
</li>
<li>
<p><a id="ref7"></a>[7] Maxime Rossi Bellom, Raphaël Neveu, Damiano Melotti, Gabrielle Viala. &ldquo;Attacking Samsung Galaxy A* Boot Chain, and Beyond.&rdquo; <em>BlackHat USA 2024</em>. <a href="https://www.blackhat.com/us-24/briefings/schedule/index.html#attacking-samsung-galaxy-a-boot-chain-and-beyond-38526" rel="noopener noreferrer" target="_blank">Link</a>
</p>
</li>
<li>
<p><a id="ref8"></a>[8] Maxime Rossi Bellom, Damiano Melotti. &ldquo;Attack on Titan M Reloaded: Vulnerability Research on a Modern Security Chip.&rdquo; <em>BlackHat USA 2022</em>. <a href="https://www.blackhat.com/us-22/briefings/schedule/#attack-on-titan-m-reloaded-vulnerability-research-on-a-modern-security-chip-27330" rel="noopener noreferrer" target="_blank">Link</a>
</p>
</li>
<li>
<p><a id="ref9"></a>[9] Maxime Rossi Bellom, Damiano Melotti. &ldquo;Attack on Titan M: Vulnerability Research on a Modern Security Chip.&rdquo; <em>TROOPERS 2022</em>. <a href="https://troopers.de/troopers22/agenda/tr22-1081-attack-on-titan-m-vulnerability-research-on-a-modern-security-chip/" rel="noopener noreferrer" target="_blank">Link</a>
</p>
</li>
<li>
<p><a id="ref10"></a>[10] Ramtine Tofighi Shirazi et al. &ldquo;Defeating Opaque Predicates Statically through Machine Learning and Binary Analysis.&rdquo; <em>SPRO 2019</em>. <a href="https://arxiv.org/pdf/1909.01640" rel="noopener noreferrer" target="_blank">PDF</a>
</p>
</li>
<li>
<p><a id="ref11"></a>[11] Ramtine Tofighi Shirazi et al. &ldquo;Fine-grained static detection of obfuscation transforms using ensemble-learning and semantic reasoning.&rdquo; <em>SSPREW 2019</em>. <a href="https://arxiv.org/pdf/1911.07523" rel="noopener noreferrer" target="_blank">PDF</a>
</p>
</li>
<li>
<p><a id="ref12"></a>[12] Maxime Rossi Bellom et al. &ldquo;When Samsung meets MediaTek: the story of a small bug chain.&rdquo; <em>SSTIC 2024</em>. <a href="https://www.sstic.org/media/SSTIC2024/SSTIC-actes/when_vendor1_meets_vendor2_the_story_of_a_small_bu/SSTIC2024-Article-when_vendor1_meets_vendor2_the_story_of_a_small_bug_chain-rossi-bellom_neveu.pdf" rel="noopener noreferrer" target="_blank">PDF</a>
</p>
</li>
<li>
<p><a id="ref13"></a>[13] Jie Lin and David Mohaisen. &ldquo;From Large to Mammoth: A Comparative Evaluation of Large Language Models in Vulnerability Detection.&rdquo; <em>NDSS 2025</em>. <a href="https://www.ndss-symposium.org/wp-content/uploads/2025-1491-paper.pdf" rel="noopener noreferrer" target="_blank">PDF</a>
</p>
</li>
<li>
<p><a id="ref14"></a>[14] Andrew Arash Mahyari. &ldquo;Harnessing the Power of LLMs in Source Code Vulnerability Detection.&rdquo; <em>IEEE MILCOM 2024</em>. <a href="https://arxiv.org/pdf/2408.03489" rel="noopener noreferrer" target="_blank">PDF</a>
</p>
</li>
</ul>
<hr>
<p><em>The SecMate Team</em></p>
]]></content:encoded><media:content url="https://blog.secmate.dev/images/og_image.jpg" medium="image"/></item></channel></rss>