Raphael Karger Blog About Security Topics and Research I Perform. 243A 91DF 4ECC 1913 4E20
C1A3 6979 302D 2CE6 6DDE

Scanning the Scanners: Compromising Five Security Vendors Through Their Own Scanners

We fed untrusted repositories to 20 hosted code scanners. Five ran our code or read outside the repo, and all five leaked the vendor's own operational credentials. The write-up behind my Black Hat USA 2026 talk.

Black Hat USA 2026: Scanning the Scanners (Slides, Deck & Tools)

Slides, tools, and links from my Black Hat USA 2026 briefing on hosted code scanners that execute the untrusted repositories they process.

Abusing OS Patch Management in GCP for Lateral Movement and Persistence

Using OS patch management in GCP to pivot and maintain access to compute instances.

Analysis and Discovery of CVE-2020-13693

Source code analysis to find privilege-escalation in 300k sites.

Context Menu persistence using DLL Hijacking

Using DLL hijacking to gain persistence in explorer.exe.