Bishop Fox

12.1K posts

Bishop Fox banner
Bishop Fox

Bishop Fox

@bishopfox

A leading provider of #offensivesecurity solutions & contributor to the #infosec community. #pentesting #hacking VC @forgepointcap @carrickcapital @WestCap8

Tempe, AZ Katılım Nisan 2013
4.3K Takip Edilen25.6K Takipçiler
Bishop Fox
Bishop Fox@bishopfox·
Thomas Wilson on the GitHub Actions cache poisoning technique behind Mini-Shai-Hulud and why CI/CD trust assumptions are becoming a major real-world attack surface, from the Initial Access podcast.
English
1
1
1
464
Bishop Fox
Bishop Fox@bishopfox·
Acompaña hoy en vivo a Juan Jasso en Hacking en la Nube 101, un taller práctico que abarca los fundamentos del pentesting en la nube, herramientas como CloudFox, las malas configuraciones y las rutas de ataque comunes en entornos cloud.
Bishop Fox tweet media
Español
1
0
1
368
Bishop Fox
Bishop Fox@bishopfox·
Happening now! Cloud environments introduce a completely different attack surface, and understanding how attackers enumerate and exploit them is becoming a core security skill. Join Juan Jasso live for Cloud Hacking 101, a hands-on workshop covering cloud pentesting fundamentals, CloudFox tooling, misconfigurations, and common cloud attack paths: bfx.social/4wFkphl
Bishop Fox tweet media
English
0
0
1
353
Bishop Fox
Bishop Fox@bishopfox·
We’re excited to host Cloud Hacking 101, our first workshop to be available in both English and Spanish! In this hands-on workshop, Juan Jasso will walk through the fundamentals of cloud penetration testing, including how to use CloudFox to enumerate cloud environments, identify misconfigurations, and safely explore common attack paths across providers. This is perfect for people who want real, practical experience!
Bishop Fox tweet media
English
1
0
1
313
Bishop Fox
Bishop Fox@bishopfox·
AI helped build a web exploitation framework faster than would’ve been realistic before. Senior Operator I Tony West shares what it was actually like building Joro with AI-assisted development, including where the models helped and where they completely hallucinated integrations.
Bishop Fox tweet mediaBishop Fox tweet mediaBishop Fox tweet mediaBishop Fox tweet media
English
1
0
2
399
Bishop Fox
Bishop Fox@bishopfox·
Happening today at 2 p.m. ET: Join AIMap creator Aashiq Ramachandran for a demo exploring how publicly exposed AI systems can be discovered, fingerprinted, scored, and tested in real time. From agent frameworks to exposed model endpoints, we’ll walk through what attackers can see and what defenders should be paying attention to!
Bishop Fox tweet media
English
7
0
1
308
Bishop Fox
Bishop Fox@bishopfox·
“What if consumers were never the real target?” Sergio Villegas and John Untz discuss the recent Daemon Tools supply chain compromise and why consumers may have just been collateral damage.
English
1
1
2
431
Bishop Fox
Bishop Fox@bishopfox·
AI systems are becoming part of the attack surface, but most teams still don’t have good visibility into what’s exposed, what tools are accessible, or how these systems behave under attack.
Bishop Fox tweet media
English
1
1
1
275
Bishop Fox
Bishop Fox@bishopfox·
How do you spot AI-generated code? Start with the comments—comments that explain every tiny thing in excruciating detail—whether you asked for it or not. Oh, and the em-dashes. Sr. Managing Operator Richard Brown explains.
English
2
0
1
584
Bishop Fox
Bishop Fox@bishopfox·
A failed login should not take 6 seconds. Bishop Fox researchers reproduced CVE-2026-42208 in LiteLLM’s proxy. The attack requires no authentication, still returns HTTP 401 responses, and uses timing delays to extract sensitive data. Observed in the wild roughly 36 hours after disclosure. Upgrade to 1.83.7 or higher.
Bishop Fox tweet mediaBishop Fox tweet mediaBishop Fox tweet mediaBishop Fox tweet media
English
1
4
11
2.8K
Bishop Fox
Bishop Fox@bishopfox·
Billy Giles is heading to Hack Space Con! His talk, "When Stealth Becomes the Enemy," challenges the idea that undetected access and complex exploit chains automatically equal success. Instead, he'll cover how to design engagements that actually improve defenses. Details: bfx.social/3PngzbR
Bishop Fox tweet media
English
0
0
2
293