# Raphael Karger > Raphael Karger is a developer, security engineer, security researcher, and co-founder and CTO of ZeroPath. His work focuses on application security, cloud security, offensive security, supply-chain risk, and tools that find exploitable software vulnerabilities. Raphael publishes security research, open-source tools, vulnerability analysis, and conference material. This is the canonical index for his personal website and public technical work. ## Primary - [Raphael Karger — canonical website](https://raphael.karger.is/): Personal homepage, verified contact paths, and PGP identity. - [Full LLM profile and research context](https://raphael.karger.is/llms-full.txt): Expanded biography, research summaries, talks, projects, and identifiers. - [Raphael's Security Blog](https://blog.raphael.karger.is/): Original technical articles and research. ## Featured research - [Scanning the Scanners: Compromising Five Security Vendors Through Their Own Scanners](https://blog.raphael.karger.is/articles/2026-08/scanning-the-scanners): Black Hat USA 2026 research into supply-chain risk in hosted code-security scanners; 20 platforms tested and five confirmed worker-boundary failures. - [Black Hat USA 2026: Scanning the Scanners](https://blog.raphael.karger.is/articles/2026-08/bh-2026): Briefing slides, open-source tools, technical write-up, and session link. - [Abusing OS Patch Management in GCP for Lateral Movement and Persistence](https://blog.raphael.karger.is/articles/2022-08/GCP-OS-Patching): Offensive use of Google Cloud OS patch jobs and deployments for cross-platform code execution, persistence, and lateral movement. - [Analysis and Discovery of CVE-2020-13693](https://blog.raphael.karger.is/articles/2020-05/CVE-2020-13693): Raphael's discovery and analysis of a critical bbPress privilege-escalation vulnerability. - [Context Menu Persistence Using DLL Hijacking](https://blog.raphael.karger.is/articles/2020-03/context-menu-persistance): Windows persistence through Explorer context-menu handlers and DLL proxying. ## Open-source security tools - [Build Canaries](https://github.com/rek7/build-canaries): Generates and validates repository artifacts that test whether scanners and build systems safely process untrusted code. - [DVASP](https://github.com/rek7/DVASP): Damn Vulnerable Application Security Platform, a deliberately vulnerable local-first target for safely testing scanner boundary failures. - [Patchy](https://github.com/rek7/patchy): Red-team tool that automates lateral movement and persistence by abusing GCP OS patch management. - [DLL hijacking](https://github.com/rek7/dll-hijacking): Code and supporting material for DLL proxying and context-menu persistence research. ## Contact and public profiles - [Email Raphael Karger](mailto:site@karger.is): Preferred direct contact address published on the canonical website. - [GitHub — rek7](https://github.com/rek7): Source code and open-source security projects. - [LinkedIn — Raphael Karger](https://www.linkedin.com/in/raphael-karger/): Professional profile. - [X — @pwnszn](https://x.com/pwnszn): Public social profile. - [PGP public key](https://raphael.karger.is/key.asc): Fingerprint `15D2 F1D7 CD0C 5DDC 2293 9EE4 E647 29E1 323A 7B75`.