Expert insights on offensive security, AI vulnerabilities, and emerging threats from Bishop Fox's leading security researchers and penetration testers.
Introducing Joro: Using AI to Build Security Tooling
May 12, 2026
By Tony West
Otto Support - The Confused Deputy
May 8, 2026
By Derek Rush
Otto Support - SSRF and Token Passthrough with MCP
May 7, 2026
By Derek Rush
CVE-2026-42208: Pre-Authentication SQL Injection in LiteLLM Proxy
May 6, 2026
By Nate Robb
Otto Support - Excessive Agency and Tool Privileges
May 6, 2026
By Derek Rush
Azure Hacking: New Cloudfoxable Challenges
May 4, 2026
By Gerben Kleijn
Introducing AIMap: Security Testing For AI Agent Infrastructure
Apr 30, 2026
By Aashiq Ramachandran
Otto Support – An MCP, Agentic-AI Security Challenge
Apr 23, 2026
By Derek Rush
Understanding the CVE Ecosystem and NIST’s Changing Role
Apr 22, 2026
By Richard Brown
Taking Maestro in Stride: AI Threat Modeling Frameworks
Apr 16, 2026
By Shad Malloy
Anthropic’s Claude Mythos Preview: The AI Cybersecurity Inflection Point
Apr 14, 2026
By Bishop Fox
Inside Cirro: Attack Paths, Cloud Graphs, and Extensible Schemas
Apr 9, 2026
By Leron Gray
API Authentication Bypass in FortiClient EMS 7.4.5-7.4.6–CVE-2026-35616
Apr 7, 2026
By John Untz
Delivered by Trust: What the Axios Supply Chain Attack Means for Security Leaders
Apr 6, 2026
By Dillon Sparks
strongSwan CVE-2026-25075: Integer Underflow in VPN Authentication
Mar 26, 2026
By Jon Williams
Accidental Engineer: Building My First Hardware Tool the Hard Way
Mar 17, 2026
By Raf Marconi
Winning CTFs: A Proving Ground at HackMex & Ekoparty
Mar 13, 2026
By Luis De la Rosa Hernandez
Pre-Authentication SQL Injection in FortiClient EMS 7.4.4 - CVE-2026-21643
Mar 9, 2026
By John Untz
Beyond Electron: Attacking Alternative Desktop Application Frameworks
Mar 3, 2026
By Carlos Yanez
Introducing CloudFox GCP: Attack Path Identification for Google Cloud
Feb 26, 2026
By Joseph Barcia
Samsung Tizen OS | Version Through 9.0
Feb 24, 2026
By Bishop Fox Researchers
AI & Security Risks: Reviewing Governance and Guardrails
Feb 19, 2026
By Bishop Fox
Most Security Programs Test a Fraction of Their Applications. That Changes Today.
Feb 9, 2026
By Rob Ragan
Deep Dive into Arista NG Firewall Vulnerabilities
Feb 9, 2026
By Ronan Kervella
This site uses cookies to provide you with a great user experience. By continuing to use our website, you consent to the use of cookies. To find out more about the cookies we use, please see our Privacy Policy.