Scanning the Scanners: Turning Security Vendors into Supply-Chain Weapons
Slides, tools, and links from my Black Hat USA 2026 briefing on hosted code scanners that execute the untrusted repositories they process.
Slides, tools, and links from my Black Hat USA 2026 briefing on hosted code scanners that execute the untrusted repositories they process.
Using OS patch management in GCP to pivot and maintain access to compute instances.
Source code analysis to find privilege-escalation in 300k sites.
Using DLL hijacking to gain persistence in explorer.exe.