AI-Powered Application Penetration Testing—Scale Security Without Compromise Learn More

Podcast header background
Initial Access Podcast

What Matters in Cybersecurity

Bishop Fox offensive security researchers and hackers take an unfiltered look at the latest cybersecurity headlines and give you a straight take. Do you actually need to care, or is it more of the same problems we’ve been seeing for years?

Initial Access cybersecurity podcast logo with stylized glitch graphics and bold red, white, and black branding.
Image
Initial Access Podcast
This Week  •  Episode 22

Pokémon GO, ServiceNow Auth Flaw, and the Anthropic Model Pulldown

Play: 55 Min

This episode explores what happens when the systems people trust quietly extend into domains they never agreed to. A Pokémon GO AR dataset trained a Visual Positioning System now adjacent to military drone navigation. A ServiceNow authentication flaw handed attackers read access to the operational core of enterprise IT. And the US government pulled two frontier AI models off the market over a jailbreak, with no established framework to bring them back.

Listen Anywhere

Watch Video Initial Access Moving up the Stack with speakers headshot and Bishop Fox Initial Access logo.
Jun 12, 2026   •   35 Min

Linux NFTables Root Exploit, Gemini Prompt Injection, and Cisco SD-WAN Zero-Day

This episode explores how the attack surface keeps expanding at every layer — from a single inverted kernel character enabling unauthenticated root, to AI assistants weaponized as system-wide IPC through notification injection, a Cisco SD-WAN zero-day giving attackers control of enterprise routing fabric, and the week's unavoidable elephant: whether Claude Fable V's guardrails actually hold.

Is this true or prob true? Initial Access Forged VPN Sessions Autonomous AI Worm and Hotel Reservation Hijacking.
Jun 5, 2026   •   48 Min

Forged VPN Sessions, Autonomous AI Worm, and Hotel Reservation Hijacking

This episode explores how attackers live in the gap between what a system can verify and what it settles for, from forged GlobalProtect VPN sessions to an autonomous AI worm, a social-engineered Meta support bot, voice-phished Salesforce access, and hotel reservation hijacking.

Initial Access Custom Payload Evasion Chained Network to Physical Breach and Satellite Hacking Red Team War Stories thumbnail with speaker headshots.
May 29, 2026   •   46 Min

Custom Payload Evasion, Chained Network-to-Physical Breach, and Satellite Hacking

This special red team episode goes inside with the Bishop Fox Red Team — exploring how AI accelerates custom payload evasion and social engineering at scale, what a chained network-to-physical breach looks like in practice, and why satellites and gas pumps are reachable from the public internet right now.

Vs code supply chain attack microsoft exchange zero day and ai accelerated vulnerability discovery thumbnail
May 27, 2026   •   26 Min

VS Code Supply Chain Attack, Microsoft Exchange Zero-Day, and AI-Accelerated Vulnerability Discovery

This episode explores how attackers exploit infrastructure that became load-bearing before anyone secured it from a malicious VS Code extension that compromised thousands of GitHub repositories and an actively exploited Exchange zero-day, to Cisco SD-WAN auth bypasses, AI chaining low-severity bugs into real attack paths, and AWS GovCloud credentials left exposed in a public repo.

Ai zero day exploit ci cd supply chain poisoning and vibe coded data exposure thumbnail
May 18, 2026   •   45 Min

AI Zero-Day Exploit, CI/CD Supply Chain Poisoning, and Vibe-Coded Data Exposure

This episode explores how modern development's trust assumptions keep failing in attackers' favor, from the first confirmed AI-written zero-day to a coordinated supply chain attack poisoning 518 million download paths, developer credential harvesting via rootkit, AWS SES abuse for phishing at scale, and thousands of vibe-coded apps leaking sensitive data in the open web.

Linux kernel exploit github rce and canvas cyberattack thumbnail
May 11, 2026   •   48 Min

Linux Kernel Exploit, GitHub RCE, and Canvas Cyberattack

This episode explores how every layer of the stack has become an attack surface — from a privilege-escalating Linux kernel flaw and a GitHub infrastructure RCE to a poisoned RubyGems supply chain, a trojanized vendor installer, and a ransomware hit on centralized education infrastructure.

Cpanel auth bypass claude ai code risks and trigona ransomware thumbnail
May 5, 2026   •   33 Min

cPanel Auth Bypass, Claude AI Code Risks, and Trigona Ransomware

This episode explores how access is being created, scaled, and kept with less friction, from a critical cPanel authentication bypass to AI-generated vulnerable code, AI-assisted attacks, persistent footholds in trusted systems, and stealthier data exfiltration.

Anthropic tool access eu app bypasses and active zero days thumbnail
Apr 28, 2026   •   31 Min

Anthropic Tool Access, EU App Bypasses, and Active Zero-Days

This episode explores how access control is breaking down across AI systems, consumer apps, and vulnerability management, from leaked AI tooling and bypassed EU verification apps to actively exploited Windows zero-days and growing strain on the NVD.

Trusted tools hijacked sessions cheap paths to big access thumbnail
Apr 22, 2026   •   31 Min

Trusted Tools, Hijacked Sessions & Cheap Paths to Big Access

This week’s episode is about attackers working through what’s already trusted. Not broken. Not bypassed. Trusted.

Project glasswing ai vulnerability discovery exploit thumbnail
Apr 13, 2026   •   22 Min

Project Glasswing: AI Vulnerability Discovery & Exploit

In this special episode, we break down Anthropic’s Project Glasswing announcement and what it signals for the future of cybersecurity.

Github malware dns hijacking ransomware speed ai exploits thumbnail
Apr 13, 2026   •   41 Min

GitHub Malware, DNS Hijacking, Ransomware Speed & AI Exploits

In this Initial Access podcast episode, we examine how trust, speed, and automation are reshaping initial access across software supply chains, network infrastructure, and AI systems.

Inherited access ai permissions supply chain attacks edge exposure thumbnail
Apr 7, 2026   •   27 Min

Inherited Access, AI Permissions, Supply Chain Attacks & Edge Exposure

In this Initial Access podcast episode, we examine how attackers are inheriting access through trusted systems, default permissions, and unpatchable infrastructure.

Malvertising trusted tools real time attacks shrinking windows thumbnail
Mar 31, 2026   •   30 Min

Malvertising, Trusted Tools, Real-Time Attacks & Shrinking Windows

In this Initial Access podcast episode, we examine how attackers are turning normal workflows and trusted systems into reliable paths for initial access as exploitation timelines continue to shrink.

Speed trust and the compromised workbench thumbnail
Mar 25, 2026   •   27 Min

Speed, Trust, and the Compromised Workbench

In this Initial Access podcast episode, the team looks at several recent examples of that compression in action, from a supply chain compromise that led to AWS admin access, to malware spreading through GitHub, npm, and VS Code, to ClickFix lures that convince technical users to run malicious commands themselves.

Social engineering phishing as a service edge device exploits ai assisted attacks thumbnail
Mar 14, 2026   •   37 Min

Social Engineering, Phishing-as-a-Service, Edge Device Exploits & AI-Assisted Attacks

In this Initial Access podcast episode, we examine how attackers are gaining initial access through social engineering, identity abuse, and vulnerable edge infrastructure.

Ai coding agents fortigate attacks surveillance identity hacks thumbnail
Mar 6, 2026   •   27 Min

AI Coding Agents, FortiGate Attacks, Surveillance & Identity Hacks

In this Initial Access podcast episode, we cover AI coding agents operating inside developer environments, automated attack platforms accelerating exploitation cycles, long-lived connected devices exposing unexpected telemetry risks, and why identity systems remain the primary entry point for attackers.

Autonomous ai broken guardrails geopolitics thumbnail
Mar 6, 2026   •   19 Min

Autonomous AI, Broken Guardrails & Geopolitics

In this Initial Access podcast episode, we cover autonomous vulnerability discovery, AI agents that ignore instructions, and why models are becoming strategic national assets.

Sso phishing patching failures exposed apis thumbnail
Mar 6, 2026   •   21 Min

SSO Phishing, Patching Failures & Exposed APIs

In this Initial Access podcast episode, we cover SSO phishing, patching failures, exposed APIs, and zombie infrastructure remind us that basic security hygiene still decides the outcome.

Deepfakes spyware skits llms for hire thumbnail
Mar 6, 2026   •   15 Min

Deepfakes, Spyware Skits & LLMs for Hire

In this Initial Access podcast episode, we cover prompt injection, a hijacked Outlook add-in, commoditized mobile spyware, AI executive deepfake scams, IT-to-OT pivoting, and nation-state use of commercial LLMs to accelerate exploitation.

Software policy rollbacks insider access abuse ai automation risk thumbnail
Mar 6, 2026   •   15 Min

Software Policy Rollbacks, Insider Access Abuse & AI Automation Risk

In this Initial Access podcast episode, we cover the rollback of federal software security guidance, insider-driven access risks, ongoing state-sponsored espionage, and the security implications of giving AI tools deep control over infrastructure.

Prompt injection session hijacking why ai isnt writing the attack plans yet thumbnail
Mar 6, 2026   •   19 Min

Prompt Injection, Session Hijacking & Why AI Isn't Writing the Attack Plans Yet

This week, we took a real look at the latest security headlines and have a straight take on them. The goal is simple: do you actually need to care about this, or is it just another variation of the same fundamental security problems we’ve been dealing with for years?