AI-Powered Application Penetration Testing—Scale Security Without Compromise Learn More

Podcast header background
Initial Access Podcast

What Matters in Cybersecurity

Bishop Fox offensive security researchers and hackers take an unfiltered look at the latest cybersecurity headlines and give you a straight take. Do you actually need to care, or is it more of the same problems we’ve been seeing for years?

Initial Access cybersecurity podcast logo with stylized glitch graphics and bold red, white, and black branding.
Image
Initial Access Custom Payload Evasion Chained Network to Physical Breach and Satellite Hacking Red Team War Stories thumbnail with speaker headshots.
This Week  •  Episode 19

Custom Payload Evasion, Chained Network-to-Physical Breach, and Satellite Hacking

Play: 46 Min

This special red team episode goes inside with the Bishop Fox Red Team — exploring how AI accelerates custom payload evasion and social engineering at scale, what a chained network-to-physical breach looks like in practice, and why satellites and gas pumps are reachable from the public internet right now.

Listen Anywhere

Vs code supply chain attack microsoft exchange zero day and ai accelerated vulnerability discovery thumbnail
May 27, 2026   •   26 Min

VS Code Supply Chain Attack, Microsoft Exchange Zero-Day, and AI-Accelerated Vulnerability Discovery

This episode explores how attackers exploit infrastructure that became load-bearing before anyone secured it from a malicious VS Code extension that compromised thousands of GitHub repositories and an actively exploited Exchange zero-day, to Cisco SD-WAN auth bypasses, AI chaining low-severity bugs into real attack paths, and AWS GovCloud credentials left exposed in a public repo.

Ai zero day exploit ci cd supply chain poisoning and vibe coded data exposure thumbnail
May 18, 2026   •   45 Min

AI Zero-Day Exploit, CI/CD Supply Chain Poisoning, and Vibe-Coded Data Exposure

This episode explores how modern development's trust assumptions keep failing in attackers' favor, from the first confirmed AI-written zero-day to a coordinated supply chain attack poisoning 518 million download paths, developer credential harvesting via rootkit, AWS SES abuse for phishing at scale, and thousands of vibe-coded apps leaking sensitive data in the open web.

Linux kernel exploit github rce and canvas cyberattack thumbnail
May 11, 2026   •   48 Min

Linux Kernel Exploit, GitHub RCE, and Canvas Cyberattack

This episode explores how every layer of the stack has become an attack surface — from a privilege-escalating Linux kernel flaw and a GitHub infrastructure RCE to a poisoned RubyGems supply chain, a trojanized vendor installer, and a ransomware hit on centralized education infrastructure.

Cpanel auth bypass claude ai code risks and trigona ransomware thumbnail
May 5, 2026   •   33 Min

cPanel Auth Bypass, Claude AI Code Risks, and Trigona Ransomware

This episode explores how access is being created, scaled, and kept with less friction, from a critical cPanel authentication bypass to AI-generated vulnerable code, AI-assisted attacks, persistent footholds in trusted systems, and stealthier data exfiltration.

Anthropic tool access eu app bypasses and active zero days thumbnail
Apr 28, 2026   •   31 Min

Anthropic Tool Access, EU App Bypasses, and Active Zero-Days

This episode explores how access control is breaking down across AI systems, consumer apps, and vulnerability management, from leaked AI tooling and bypassed EU verification apps to actively exploited Windows zero-days and growing strain on the NVD.

Trusted tools hijacked sessions cheap paths to big access thumbnail
Apr 22, 2026   •   31 Min

Trusted Tools, Hijacked Sessions & Cheap Paths to Big Access

This week’s episode is about attackers working through what’s already trusted. Not broken. Not bypassed. Trusted.

Project glasswing ai vulnerability discovery exploit thumbnail
Apr 13, 2026   •   22 Min

Project Glasswing: AI Vulnerability Discovery & Exploit

In this special episode, we break down Anthropic’s Project Glasswing announcement and what it signals for the future of cybersecurity.

Github malware dns hijacking ransomware speed ai exploits thumbnail
Apr 13, 2026   •   41 Min

GitHub Malware, DNS Hijacking, Ransomware Speed & AI Exploits

In this Initial Access podcast episode, we examine how trust, speed, and automation are reshaping initial access across software supply chains, network infrastructure, and AI systems.

Inherited access ai permissions supply chain attacks edge exposure thumbnail
Apr 7, 2026   •   27 Min

Inherited Access, AI Permissions, Supply Chain Attacks & Edge Exposure

In this Initial Access podcast episode, we examine how attackers are inheriting access through trusted systems, default permissions, and unpatchable infrastructure.

Malvertising trusted tools real time attacks shrinking windows thumbnail
Mar 31, 2026   •   30 Min

Malvertising, Trusted Tools, Real-Time Attacks & Shrinking Windows

In this Initial Access podcast episode, we examine how attackers are turning normal workflows and trusted systems into reliable paths for initial access as exploitation timelines continue to shrink.

Speed trust and the compromised workbench thumbnail
Mar 25, 2026   •   27 Min

Speed, Trust, and the Compromised Workbench

In this Initial Access podcast episode, the team looks at several recent examples of that compression in action, from a supply chain compromise that led to AWS admin access, to malware spreading through GitHub, npm, and VS Code, to ClickFix lures that convince technical users to run malicious commands themselves.

Social engineering phishing as a service edge device exploits ai assisted attacks thumbnail
Mar 14, 2026   •   37 Min

Social Engineering, Phishing-as-a-Service, Edge Device Exploits & AI-Assisted Attacks

In this Initial Access podcast episode, we examine how attackers are gaining initial access through social engineering, identity abuse, and vulnerable edge infrastructure.

Ai coding agents fortigate attacks surveillance identity hacks thumbnail
Mar 6, 2026   •   27 Min

AI Coding Agents, FortiGate Attacks, Surveillance & Identity Hacks

In this Initial Access podcast episode, we cover AI coding agents operating inside developer environments, automated attack platforms accelerating exploitation cycles, long-lived connected devices exposing unexpected telemetry risks, and why identity systems remain the primary entry point for attackers.

Autonomous ai broken guardrails geopolitics thumbnail
Mar 6, 2026   •   19 Min

Autonomous AI, Broken Guardrails & Geopolitics

In this Initial Access podcast episode, we cover autonomous vulnerability discovery, AI agents that ignore instructions, and why models are becoming strategic national assets.

Sso phishing patching failures exposed apis thumbnail
Mar 6, 2026   •   21 Min

SSO Phishing, Patching Failures & Exposed APIs

In this Initial Access podcast episode, we cover SSO phishing, patching failures, exposed APIs, and zombie infrastructure remind us that basic security hygiene still decides the outcome.

Deepfakes spyware skits llms for hire thumbnail
Mar 6, 2026   •   15 Min

Deepfakes, Spyware Skits & LLMs for Hire

In this Initial Access podcast episode, we cover prompt injection, a hijacked Outlook add-in, commoditized mobile spyware, AI executive deepfake scams, IT-to-OT pivoting, and nation-state use of commercial LLMs to accelerate exploitation.

Software policy rollbacks insider access abuse ai automation risk thumbnail
Mar 6, 2026   •   15 Min

Software Policy Rollbacks, Insider Access Abuse & AI Automation Risk

In this Initial Access podcast episode, we cover the rollback of federal software security guidance, insider-driven access risks, ongoing state-sponsored espionage, and the security implications of giving AI tools deep control over infrastructure.

Prompt injection session hijacking why ai isnt writing the attack plans yet thumbnail
Mar 6, 2026   •   19 Min

Prompt Injection, Session Hijacking & Why AI Isn't Writing the Attack Plans Yet

This week, we took a real look at the latest security headlines and have a straight take on them. The goal is simple: do you actually need to care about this, or is it just another variation of the same fundamental security problems we’ve been dealing with for years?

This site uses cookies to provide you with a great user experience. By continuing to use our website, you consent to the use of cookies. To find out more about the cookies we use, please see our Privacy Policy.