MEET THE TEAM AT BLACK HAT - DEF CON 2026 Learn More

Podcast header background
Initial Access Podcast

What Matters in Cybersecurity

Bishop Fox offensive security researchers and hackers take an unfiltered look at the latest cybersecurity headlines and give you a straight take. Do you actually need to care, or is it more of the same problems we’ve been seeing for years?

Initial Access cybersecurity podcast logo with stylized glitch graphics and bold red, white, and black branding.
Image
Watch Video Initial Access Trust Was The Exploit Rogue Agents, Bounty Cuts & the AI Brake Pedal.
This Week  •  Episode 28

Rogue Agents, Bounty Cuts & the AI Brake Pedal

Play: 59 Min

This episode covers a ChatGPT flaw that let one link spin up a fully authorized rogue AI agent, GitHub's public bug bounty cuts, Origin Energy's second breach in months, and 1,100+ AI lab employees asking Washington to help pace AI development, plus a sit-down with Bishop Fox's Dan Petro on catching cheaters in Super Smash Bros. Melee.

Listen Anywhere

Watch Video Initial Access Whos Really in Control Rogue Agents, Invisible Screens, and a Vulnerability Clearinghouse.
Jul 24, 2026   •   63 Min

Rogue Agents, Invisible Screens, and a Vulnerability Clearinghouse

This episode breaks down OpenAI's own AI agent hacking into Hugging Face without human direction, an Android attack that hides commands in invisible screen text to hijack AI phone agents, and the White House's new Gold Eagle vulnerability clearinghouse, plus a sit-down with Bishop Fox's Emilio Gallegos on snowpick, his new open-source ServiceNow exposure scanner.

Watch Video Initial Access Young Attackers Big Mistakes Attribution and Op Sec at Scale.
Jul 17, 2026   •   43 Min

Attribution and OpSec at Scale

This special Red Team episode goes inside with the Bishop Fox Red Team, talking through what attribution actually looks like when device-level telemetry breaks anonymity, what young attackers with real skills but zero tradecraft have in common, and how one credential reset becomes the master key to everything downstream.

Watch Video Initial Access You Only Fail Once Old Backdoors, Ghost Phishing, and Borrowed AI.
Jul 10, 2026   •   38 Min

Old Backdoors, Ghost Phishing, and Borrowed AI

A three-year-old router backdoor makes fresh headlines, a phishing kit called EvilTokens hides until a victim's browser builds it, and CISA turns Anthropic's Mythos model on the government's own code.

Initial Access The Window Already Closed Cisco Root Access, FortiBleed Credentials, Sparkplug Fuzzing, AI Arms Race.
Jul 2, 2026   •   48 Min

Cisco Root Access, FortiBleed Credentials, Sparkplug Fuzzing, AI Arms Race

This episode breaks down a Cisco flaw exploited within 24 hours of disclosure, a credential-harvesting campaign that hit 430,000+ FortiGate firewalls, and what Fable's restricted return and China's Tulongfeng mean for controlling offensive AI. Plus, a sit-down with Bishop Fox's Shad Malloy on building the first open-source Sparkplug B fuzzer for ICS environments.

Initial Access Podcast Hacking the World Cup FIFA Takeover, FFMpeg RCE, Klue Breach, Hardware Hacking.
Jun 26, 2026   •   51 Min

FIFA Takeover, FFMpeg RCE, Klue Breach, Hardware Hacking

This episode looks at how trusted systems become attacker pathways, from FIFA’s identity and authorization breakdown to FFmpeg’s downstream exposure, Klue’s abused OAuth access, and residential proxy networks that make malicious traffic look ordinary.

Initial Access Podcast
Jun 19, 2026   •   55 Min

Pokémon GO, ServiceNow Auth Flaw, and the Anthropic Model Pulldown

This episode explores what happens when the systems people trust quietly extend into domains they never agreed to. A Pokémon GO AR dataset trained a Visual Positioning System now adjacent to military drone navigation. A ServiceNow authentication flaw handed attackers read access to the operational core of enterprise IT. And the US government pulled two frontier AI models off the market over a jailbreak, with no established framework to bring them back.

Watch Video Initial Access Moving up the Stack with speakers headshot and Bishop Fox Initial Access logo.
Jun 12, 2026   •   35 Min

Linux NFTables Root Exploit, Gemini Prompt Injection, and Cisco SD-WAN Zero-Day

This episode explores how the attack surface keeps expanding at every layer — from a single inverted kernel character enabling unauthenticated root, to AI assistants weaponized as system-wide IPC through notification injection, a Cisco SD-WAN zero-day giving attackers control of enterprise routing fabric, and the week's unavoidable elephant: whether Claude Fable V's guardrails actually hold.

Is this true or prob true? Initial Access Forged VPN Sessions Autonomous AI Worm and Hotel Reservation Hijacking.
Jun 5, 2026   •   48 Min

Forged VPN Sessions, Autonomous AI Worm, and Hotel Reservation Hijacking

This episode explores how attackers live in the gap between what a system can verify and what it settles for, from forged GlobalProtect VPN sessions to an autonomous AI worm, a social-engineered Meta support bot, voice-phished Salesforce access, and hotel reservation hijacking.

Initial Access Custom Payload Evasion Chained Network to Physical Breach and Satellite Hacking Red Team War Stories thumbnail with speaker headshots.
May 29, 2026   •   46 Min

Custom Payload Evasion, Chained Network-to-Physical Breach, and Satellite Hacking

This special red team episode goes inside with the Bishop Fox Red Team — exploring how AI accelerates custom payload evasion and social engineering at scale, what a chained network-to-physical breach looks like in practice, and why satellites and gas pumps are reachable from the public internet right now.

Watch Initial Access Supply Chain on Fire VS code supply chain attack, Microsoft exchange zero day and AI accelerated vulnerability discovery.
May 27, 2026   •   26 Min

VS Code Supply Chain Attack, Microsoft Exchange Zero-Day, and AI-Accelerated Vulnerability Discovery

This episode explores how attackers exploit infrastructure that became load-bearing before anyone secured it from a malicious VS Code extension that compromised thousands of GitHub repositories and an actively exploited Exchange zero-day, to Cisco SD-WAN auth bypasses, AI chaining low-severity bugs into real attack paths, and AWS GovCloud credentials left exposed in a public repo.

Watch Initial Access When Vibes Get You Hacked AI zero-day exploit CI/CD supply chain poisoning and vibe coded data exposure.
May 18, 2026   •   45 Min

AI Zero-Day Exploit, CI/CD Supply Chain Poisoning, and Vibe-Coded Data Exposure

This episode explores how modern development's trust assumptions keep failing in attackers' favor, from the first confirmed AI-written zero-day to a coordinated supply chain attack poisoning 518 million download paths, developer credential harvesting via rootkit, AWS SES abuse for phishing at scale, and thousands of vibe-coded apps leaking sensitive data in the open web.

Watch Initial Access Every Layer Compromised Linux kernel exploit GitHub RCEand canvas cyberattack.
May 11, 2026   •   48 Min

Linux Kernel Exploit, GitHub RCE, and Canvas Cyberattack

This episode explores how every layer of the stack has become an attack surface — from a privilege-escalating Linux kernel flaw and a GitHub infrastructure RCE to a poisoned RubyGems supply chain, a trojanized vendor installer, and a ransomware hit on centralized education infrastructure.

Watch Initial Access AI Wrote the Vuln cPanel auth bypass Claude AI code risks and Trigona ransomware/
May 5, 2026   •   33 Min

cPanel Auth Bypass, Claude AI Code Risks, and Trigona Ransomware

This episode explores how access is being created, scaled, and kept with less friction, from a critical cPanel authentication bypass to AI-generated vulnerable code, AI-assisted attacks, persistent footholds in trusted systems, and stealthier data exfiltration.

Watch Initial Access Access Control is Broken Anthropic tool access EU app bypasses and active zero days.
Apr 28, 2026   •   31 Min

Anthropic Tool Access, EU App Bypasses, and Active Zero-Days

This episode explores how access control is breaking down across AI systems, consumer apps, and vulnerability management, from leaked AI tooling and bypassed EU verification apps to actively exploited Windows zero-days and growing strain on the NVD.

Watch Initial Access Trust is the Exploit Trusted tools hijacked sessions cheap paths to big access.
Apr 22, 2026   •   31 Min

Trusted Tools, Hijacked Sessions & Cheap Paths to Big Access

This week’s episode is about attackers working through what’s already trusted. Not broken. Not bypassed. Trusted.

Watch Initial Access Project Glasswing AI vulnerability discovery exploit.
Apr 13, 2026   •   22 Min

Project Glasswing: AI Vulnerability Discovery & Exploit

In this special episode, we break down Anthropic’s Project Glasswing announcement and what it signals for the future of cybersecurity.

Watch Initial Access Speed Kills Defenders Github malware dns hijacking ransomware speed AI exploits.
Apr 10, 2026   •   41 Min

GitHub Malware, DNS Hijacking, Ransomware Speed & AI Exploits

In this Initial Access podcast episode, we examine how trust, speed, and automation are reshaping initial access across software supply chains, network infrastructure, and AI systems.

Watch Initial Access Inherited and Exploited Inherited access AI permissions supply chain attacks edge exposure.
Apr 7, 2026   •   27 Min

Inherited Access, AI Permissions, Supply Chain Attacks & Edge Exposure

In this Initial Access podcast episode, we examine how attackers are inheriting access through trusted systems, default permissions, and unpatchable infrastructure.

Watch Initial Access No Time To Patch Malvertising trusted tools real time attacks shrinking windows.
Mar 27, 2026   •   30 Min

Malvertising, Trusted Tools, Real-Time Attacks & Shrinking Windows

In this Initial Access podcast episode, we examine how attackers are turning normal workflows and trusted systems into reliable paths for initial access as exploitation timelines continue to shrink.

Watch Initial Access Your Workbench is Infected Speed trust and the compromised workbench.
Mar 20, 2026   •   36 Min

Speed, Trust, and the Compromised Workbench

In this Initial Access podcast episode, the team looks at several recent examples of that compression in action, from a supply chain compromise that led to AWS admin access, to malware spreading through GitHub, npm, and VS Code, to ClickFix lures that convince technical users to run malicious commands themselves.

Watch Initial Access Phishing Goes Industrial Social engineering phishing as a service edge device exploits AI assisted attacks.
Mar 14, 2026   •   37 Min

Social Engineering, Phishing-as-a-Service, Edge Device Exploits & AI-Assisted Attacks

In this Initial Access podcast episode, we examine how attackers are gaining initial access through social engineering, identity abuse, and vulnerable edge infrastructure.

Watch Initial Access Identity is the Perimeter AI coding agents Fortigate attacks surveillance identity hacks.
Mar 6, 2026   •   27 Min

AI Coding Agents, FortiGate Attacks, Surveillance & Identity Hacks

In this Initial Access podcast episode, we cover AI coding agents operating inside developer environments, automated attack platforms accelerating exploitation cycles, long-lived connected devices exposing unexpected telemetry risks, and why identity systems remain the primary entry point for attackers.

Watch Initial Access AI Off The Leash Autonomous AI broken guardrails geopolitics.
Feb 27, 2026   •   19 Min

Autonomous AI, Broken Guardrails & Geopolitics

In this Initial Access podcast episode, we cover autonomous vulnerability discovery, AI agents that ignore instructions, and why models are becoming strategic national assets.

Watch Initial Access One Login, Full Access SSO phishing patching failures exposed apis.
Feb 20, 2026   •   21 Min

SSO Phishing, Patching Failures & Exposed APIs

In this Initial Access podcast episode, we cover SSO phishing, patching failures, exposed APIs, and zombie infrastructure remind us that basic security hygiene still decides the outcome.

Watch Initial Access Hackers-As-A-Service Deepfakes spyware skits llms for hire.
Feb 13, 2026   •   15 Min

Deepfakes, Spyware Skits & LLMs for Hire

In this Initial Access podcast episode, we cover prompt injection, a hijacked Outlook add-in, commoditized mobile spyware, AI executive deepfake scams, IT-to-OT pivoting, and nation-state use of commercial LLMs to accelerate exploitation.

Initial Access Insider Thread Scaled Software policy rollbacks insider access abuse ai automation risk.
Feb 6, 2026   •   15 Min

Software Policy Rollbacks, Insider Access Abuse & AI Automation Risk

In this Initial Access podcast episode, we cover the rollback of federal software security guidance, insider-driven access risks, ongoing state-sponsored espionage, and the security implications of giving AI tools deep control over infrastructure.

Initial Access Hijacked by Design Prompt injection session hijacking why ai isnt writing the attack plans yet.
Jan 23, 2026   •   19 Min

Prompt Injection, Session Hijacking & Why AI Isn't Writing the Attack Plans Yet

This week, we took a real look at the latest security headlines and have a straight take on them. The goal is simple: do you actually need to care about this, or is it just another variation of the same fundamental security problems we’ve been dealing with for years?