Please turn JavaScript on

Raphael's Security Blog

Follow Raphael's Security Blog's news and updates in a matter of seconds! We will deliver any update via email, phone or you can read them from here on the site on your own news page.

You can even combine different feeds with the feed for Raphael's Security Blog.

Subscribing and unsubscribing is fast, easy and risk free.

The whole service is free of cost.

Raphael's Security Blog: Raphael's Security Blog

Is this your feed? Claim it!

Publisher:  Unclaimed!
Message frequency:  0.14 / day

Message History

This is the written companion to my Black Hat USA 2026 briefing, Scanning the Scanners: Turning Security Vendors into Supply-Chain Weapons. That page has the slides, the open-source tooling, and the session listing.

One definition first, because the whole ...


Read full story

This page has the slide deck from my Black Hat USA 2026 briefing, the two open-source releases, and the session listing.

Supply-chain compromise usually runs one way. A vendor gets breached, and the damage flows downstream through its distribution channel. This research tests the reverse path, where a hosted code scanner accepts repositories from anyone who signs up...


Read full story