Bishop Fox
12.1K posts

Bishop Fox
@bishopfox
A leading provider of #offensivesecurity solutions & contributor to the #infosec community. #pentesting #hacking VC @forgepointcap @carrickcapital @WestCap8
Tempe, AZ Katılım Nisan 2013
4.3K Takip Edilen25.6K Takipçiler

Happening now!
Cloud environments introduce a completely different attack surface, and understanding how attackers enumerate and exploit them is becoming a core security skill.
Join Juan Jasso live for Cloud Hacking 101, a hands-on workshop covering cloud pentesting fundamentals, CloudFox tooling, misconfigurations, and common cloud attack paths: bfx.social/4wFkphl

English

Sign up here or through our Discord server!
English (May 20): bfx.social/497jH2q
Español: (21 Mayo): bfx.social/4dp7JCu
Discord: bfx.social/4dLFSxF
English

We’re excited to host Cloud Hacking 101, our first workshop to be available in both English and Spanish!
In this hands-on workshop, Juan Jasso will walk through the fundamentals of cloud penetration testing, including how to use CloudFox to enumerate cloud environments, identify misconfigurations, and safely explore common attack paths across providers.
This is perfect for people who want real, practical experience!

English

Happening today at 2 p.m. ET:
Join AIMap creator Aashiq Ramachandran for a demo exploring how publicly exposed AI systems can be discovered, fingerprinted, scored, and tested in real time.
From agent frameworks to exposed model endpoints, we’ll walk through what attackers can see and what defenders should be paying attention to!

English

We’re demoing our new open-source tool, AIMap, on May 14: bfx.social/4tvAFPg
English

A failed login should not take 6 seconds.
Bishop Fox researchers reproduced CVE-2026-42208 in LiteLLM’s proxy. The attack requires no authentication, still returns HTTP 401 responses, and uses timing delays to extract sensitive data.
Observed in the wild roughly 36 hours after disclosure.
Upgrade to 1.83.7 or higher.




English

Billy Giles is heading to Hack Space Con!
His talk, "When Stealth Becomes the Enemy," challenges the idea that undetected access and complex exploit chains automatically equal success. Instead, he'll cover how to design engagements that actually improve defenses.
Details: bfx.social/3PngzbR

English





