Expert insights on offensive security, AI vulnerabilities, and emerging threats from Bishop Fox's leading security researchers and penetration testers.
Mythos Doesn't Deploy Itself
Jun 9, 2026
By Vincent Liu
Popping Root on UniFi OS Server: Unauthenticated RCE Chain Detection & Analysis
Jun 5, 2026
By Jon Williams
Otto Support - Testing MCP Servers
Jun 3, 2026
By Michael Cheng
Looting UniFi Controllers: Detecting and Weaponizing CVE-2026-22557
May 29, 2026
By Jon Williams
Sparkplug B Protocol Fuzzing with AI Assistance
May 26, 2026
By David Colón, Shad Malloy
Detecting CVE-2026-0265 at Scale: PAN-OS CAS Authentication Bypass
May 22, 2026
By Jon Williams, John Untz, Bishop Fox Researchers
CVE-2026-27886: Unauthenticated Boolean-Oracle Exfiltration of Administrator Secrets in Strapi
May 22, 2026
By Nate Robb
Otto Support - Logging and Visibility in MCP Servers
May 14, 2026
By Derek Rush
Otto-Support - Supply Chain Risks in MCP Servers
May 13, 2026
By Derek Rush
Introducing Joro: Using AI to Build Security Tooling
May 12, 2026
By Tony West
Otto Support - The Confused Deputy
May 8, 2026
By Derek Rush
Otto Support - SSRF and Token Passthrough with MCP
May 7, 2026
By Derek Rush
Otto Support - Excessive Agency and Tool Privileges
May 6, 2026
By Derek Rush
CVE-2026-42208: Pre-Authentication SQL Injection in LiteLLM Proxy
May 6, 2026
By Nate Robb
Azure Hacking: New Cloudfoxable Challenges
May 4, 2026
By Gerben Kleijn
Introducing AIMap: Security Testing For AI Agent Infrastructure
Apr 30, 2026
By Aashiq Ramachandran
Otto Support – An MCP, Agentic-AI Security Challenge
Apr 23, 2026
By Derek Rush
Understanding the CVE Ecosystem and NIST’s Changing Role
Apr 22, 2026
By Richard Brown
Taking Maestro in Stride: AI Threat Modeling Frameworks
Apr 16, 2026
By Shad Malloy
Anthropic’s Claude Mythos Preview: The AI Cybersecurity Inflection Point
Apr 14, 2026
By Bishop Fox
Inside Cirro: Attack Paths, Cloud Graphs, and Extensible Schemas
Apr 9, 2026
By Leron Gray
API Authentication Bypass in FortiClient EMS 7.4.5-7.4.6–CVE-2026-35616
Apr 7, 2026
By John Untz
Delivered by Trust: What the Axios Supply Chain Attack Means for Security Leaders
Apr 6, 2026
By Dillon Sparks
strongSwan CVE-2026-25075: Integer Underflow in VPN Authentication
Mar 26, 2026
By Jon Williams
This site uses cookies to provide you with a great user experience. By continuing to use our website, you consent to the use of cookies. To find out more about the cookies we use, please see our Privacy Policy.