Sign in

Bishop Fox

@bishopfox.bsky.social
176 followers 28 following 331 posts

A leading provider of #offensivesecurity solutions & contributor to the #infosec community. #pentesting #hacking

PostsRepliesMedia
Bishop Fox @bishopfox.bsky.social · 20h
Discord de Bishop Fox: okt.to/iaE7zP
okt.to
Join the Bishop Fox Discord Server!
RedSec is an offensive cybersecurity server by Bishop Fox. The server is a friendly space for infosec professionals! | 2127 members
000
Bishop Fox @bishopfox.bsky.social · 20h
¡Hoy tenemos taller en español! Samanta Aranda nos enseñará cómo aprovechar configuraciones incorrectas de CloudFormation para escalar privilegios en AWS. Un taller práctico sobre IAM, roles de servicio y rutas de ataque.
100
Bishop Fox @bishopfox.bsky.social · 21h
More from our conversation on security priorities for 2027: okt.to/bcxqU1
okt.to
AI Security, Risk, and Cybersecurity Priorities for 2027
Vinnie Liu, Justin Greis, and Evan Wolff discuss AI security, risk, and which cybersecurity investments will actually matter heading into 2027.
000
Bishop Fox @bishopfox.bsky.social · 21h
Who has the AI advantage right now? Evan Wolff says attackers. But as AI becomes embedded into everyday security tools, he expects defenders to start closing the gap.
100
Bishop Fox @bishopfox.bsky.social · 06/10/2026
Tomorrow at Ekoparty: iOS Game Hacking: From Zero to God Mode Luis De la Rosa & Steeven Rodríguez are taking over the Mobile Hacking Village with live reverse engineering, hooking, Infinite Coins, Speed Hacks and God Mode. Sala C2 2 PM ART bfx.social/4rR0oT6
000
Bishop Fox @bishopfox.bsky.social · 06/10/2026
bfx.social/4zh15rd
bfx.social
Weaponizing CloudFormation
Learn to exploit misconfigured AWS CloudFormation roles in this hands-on workshop covering IAM abuse, persistence, and delegated execution attacks.
000
Bishop Fox @bishopfox.bsky.social · 06/10/2026
Happening today: Weaponizing CloudFormation Samanta Aranda is going hands-on with how attackers can turn limited IAM permissions and misconfigured CloudFormation roles into paths to more access.
100
Bishop Fox @bishopfox.bsky.social · 05/10/2026
bfx.social/4zlFjCV
bfx.social
Ekoparty 2026
Bishop Fox's Jon Williams demos a full UniFi OS RCE chain at Ekoparty 2026 and reveals how AI tooling carried the research from firmware to exploit.
010
Bishop Fox @bishopfox.bsky.social · 05/10/2026
@Jon Williams gave an AI-powered vulnerability research lab raw UniFi firmware. It helped take the research all the way to a working unauthenticated exploit. This week at Ekoparty, Jon is demoing the takeover live and sharing where the AI worked and where it fell flat.
120
Bishop Fox @bishopfox.bsky.social · 05/10/2026
bfx.social/4hxERLC
bfx.social
ShinyHunters PeopleSoft WAF Bypass, Arrests, And OpenAI Astra News
Read about ShinyHunters PeopleSoft WAF bypass, a key arrest, 400k Medicaid records exposed, and OpenAI pulling GPT-6.1 Astra.
010
Bishop Fox @bishopfox.bsky.social · 05/10/2026
What does “no evidence of exploitation” mean when your telemetry couldn't distinguish legitimate access from abuse? Thomas Wilson breaks down the bigger lesson from the DC healthcare data exposure in the latest Initial Access.
110
Bishop Fox @bishopfox.bsky.social · 05/10/2026
http:// → blocked hTtp:// → private IP access Berenice Flores found two vulnerabilities in Zilliz Attu 2.6.5 that could be chained to reach internal services and, in a tested AWS EKS deployment, compromise the Kubernetes namespace. Upgrade to 3.0.0. bfx.social/4y26gdu
010
Bishop Fox @bishopfox.bsky.social · 02/10/2026
English (Oct 6): bfx.social/4ynFoFP Spanish (Oct 8): bfx.social/4ean7nj
bfx.social
CloudFormation bajo la mirada de un atacante
Aprende a explotar roles de AWS CloudFormation mal configurados en este taller práctico sobre abuso de IAM, persistencia y ejecución delegada en la nube.
000
Bishop Fox @bishopfox.bsky.social · 02/10/2026
Happening next week: Weaponizing CloudFormation Samanta Aranda is going hands-on with how misconfigured CloudFormation execution roles can create paths to privilege escalation and persistence in AWS. Available on our site or in the Bishop Fox Discord server!
100
Bishop Fox @bishopfox.bsky.social · 01/10/2026
Read the full breakdown: bfx.social/46Xcb8I
000
Bishop Fox @bishopfox.bsky.social · 01/10/2026
Finding more vulnerabilities doesn't help much if you can't really tell what matters. Ori Zigindere explains CTEM and how continuous scoping, prioritization, validation, and remediation can turn an endless backlog into actual risk reduction.
110
Bishop Fox @bishopfox.bsky.social · 29/09/2026
🔴 And we’re live! Vinnie Liu, Justin Greis, and Evan Wolff are talking AI security, identity risk, and the cybersecurity priorities shaping 2027. Join the conversation: bfx.social/4hlCdbT
000
Bishop Fox @bishopfox.bsky.social · 28/09/2026
See you there: bfx.social/4hv3jMt
bfx.social
AI Security, Risk, and Cybersecurity Priorities for 2027
Vinnie Liu, Justin Greis, and Evan Wolff discuss AI security, risk, and which cybersecurity investments will actually matter heading into 2027.
000
Bishop Fox @bishopfox.bsky.social · 28/09/2026
Happening tomorrow at 2 PM ET. Vinnie Liu, Justin Greis, and Evan Wolff are getting together to talk AI security, identity risk, and the cybersecurity decisions organizations should be thinking about now as 2027 approaches.
100
Bishop Fox @bishopfox.bsky.social · 28/09/2026
From the latest Initial Access: bfx.social/4jryaMm
bfx.social
Zero-Click Exchange RCE, $25 AI Intrusions, and the ShinyHunters FBI...
Exchange zero-click RCE, AI agents hitting retailers for $25, ShinyHunters claiming the FBI, OpenAI misalignment disclosures, and the MikroTick chain.
010
Bishop Fox @bishopfox.bsky.social · 28/09/2026
Attackers can now build an AI team. Kendrick Urbaniak breaks down a campaign where different models were chosen for different jobs, using one for orchestration and others with looser restrictions for exploitation.
100
Bishop Fox @bishopfox.bsky.social · 25/09/2026
Full episode: bfx.social/4hIXn3H
bfx.social
What AI Fundamentally Changed with Daniel Wallance, McKinsey
Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.
000
Bishop Fox @bishopfox.bsky.social · 25/09/2026
The questions that matter most in cybersecurity aren't always technical. Daniel Wallace of McKinsey explains why AI's shift to a non-deterministic world is changing how leaders think about risk, governance, and what actually deserves attention.
100
Bishop Fox @bishopfox.bsky.social · 24/09/2026
If you're attending, don't miss it! bfx.social/46HOTUg
bfx.social
BSides Cleveland 2026
Bishop Fox's David Garlak joins BSides Cleveland 2026 to map AWS attack paths beyond IAM, covering identity, network, and resource boundaries.
000
Bishop Fox @bishopfox.bsky.social · 24/09/2026
Most AWS attack paths begin with IAM permissions. At BSides Cleveland this Saturday, David Garlak explores what happens when you look beyond IAM and map attack paths across identity, network, and resource boundaries.
100
Bishop Fox @bishopfox.bsky.social · 23/09/2026
bfx.social/4AJlaYW
bfx.social
CVE-2026-82329: Unauthenticated Administrative Access in JFrog...
CVE-2026-82329 is a CVSS 9.8 JFrog Artifactory auth bypass where an empty cluster join key grants unauthenticated admin access. KEV-listed, patch now.
001
Bishop Fox @bishopfox.bsky.social · 23/09/2026
A secret is only useful if it actually exists. Nate Robb and the Bishop Fox Threat Enablement & Analysis Team break down how an empty cluster join key led to unauthenticated admin access in default JFrog Artifactory installs and how to safely detect it.
100
Bishop Fox @bishopfox.bsky.social · 22/09/2026
Sign up here: bfx.social/4y5Rzab
bfx.social
AI Security, Risk, and Cybersecurity Priorities for 2027
Vinnie Liu, Justin Greis, and Evan Wolff discuss AI security, risk, and which cybersecurity investments will actually matter heading into 2027.
000
Bishop Fox @bishopfox.bsky.social · 22/09/2026
The security priorities for 2027 are already taking shape. Join Vinnie Liu, Justin Greis, and Evan Wolff on Sept. 29 for a discussion on AI security, identity risk, and the cybersecurity investments that matter heading into 2027.
100
Bishop Fox @bishopfox.bsky.social · 21/09/2026
Full episode out now: bfx.social/4jgybTl
bfx.social
Ten-Hour Breaches, MikroTik Backdoors, Router Takeovers & the...
AI agents cut red team work to ten hours, MikroTik admins handed over via two CVEs, Revolut fooled by a fake gov request, and a NetScaler bypass deep dive.
000
Bishop Fox @bishopfox.bsky.social · 21/09/2026
“The map is not the territory.” A critical CVSS score tells you something. It doesn’t tell you everything. In the latest Initial Access, @Jon Williams talks about his NetScaler research and why defenders need to look beyond the advisory to understand what a CVE actually means for their environment.
100
Bishop Fox @bishopfox.bsky.social · 21/09/2026
Full research: bfx.social/3VHin26
000
Bishop Fox @bishopfox.bsky.social · 21/09/2026
A patched router can still belong to the attacker. Our latest RouterOS research reproduces the MikroTrick takeover chain and examines persistence found on real devices including privileged accounts, scripts, and scheduled tasks that can survive after logs are gone. Patch. Then investigate.
100
Bishop Fox @bishopfox.bsky.social · 17/09/2026
Full episode: bfx.social/4jaYlXz
bfx.social
AI, Attention, and the Future of Security Leadership with Christie Terrill, Bishop Fox
Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.
000
Bishop Fox @bishopfox.bsky.social · 17/09/2026
The conversation around AI is shifting from whether to use it to where human judgment still matters most. Bishop Fox CISO Christie Terrill shares why protecting time to think, building good governance, and knowing when to trust AI are becoming essential leadership skills.
100
Bishop Fox @bishopfox.bsky.social · 15/09/2026
English (6 Oct.): bfx.social/4h2TODW Español (8 Oct.): bfx.social/4j5BVqH We’ll see you in October!
bfx.social
CloudFormation bajo la mirada de un atacante
Aprende a explotar roles de AWS CloudFormation mal configurados en este taller práctico sobre abuso de IAM, persistencia y ejecución delegada en la nube.
000
Bishop Fox @bishopfox.bsky.social · 15/09/2026
Schedule update: Our Weaponizing CloudFormation workshops originally scheduled to start today have been rescheduled. Apologies for the last-minute change, and thanks for understanding.
100
Bishop Fox @bishopfox.bsky.social · 11/09/2026
The login screen should be a security boundary. But in vulnerable SolarWinds Web Help Desk versions, an attacker who knew a valid username could forge a SAML response and authenticate with a single HTTP request.
000
Bishop Fox @bishopfox.bsky.social · 10/09/2026
Join us live on Discord: English: Sept 15 - bfx.social/4iQVMK8 Español: Sept 17 - bfx.social/4ioiyc7
000
Bishop Fox @bishopfox.bsky.social · 10/09/2026
CloudFormation is supposed to automate deployments, but what happens when it has more permissions than you do? Next week, Samanta Aranda shows how attackers abuse misconfigured execution roles, iam:PassRole, and Lambda-backed Custom Resources to escalate privileges and establish persistence in AWS.
100
Bishop Fox @bishopfox.bsky.social · 09/09/2026
Watch the latest episode of Block Out the Noise: bfx.social/4xrDHGo
bfx.social
The Future of Deepfakes is Here with Tom Cross, GetReal Security
Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.
000
Bishop Fox @bishopfox.bsky.social · 09/09/2026
"I'd know if it was fake." Would you, though? @decius.bsky.social says most people underestimate how quickly AI-generated voice and video are improving. The next 12–18 months are going to change what we trust online.
100
Bishop Fox @bishopfox.bsky.social · 04/09/2026
English Session (Sept 15): bfx.social/4idF9bs Spanish Session (Sept 17): bfx.social/4yixf57
010
Bishop Fox @bishopfox.bsky.social · 04/09/2026
CloudFormation can become an attack path when execution roles have more permissions than the user invoking them. On Sept. 15 (English) and Sept. 17 (Spanish), Samanta Aranda walks through real privilege escalation and persistence techniques using misconfigured CloudFormation execution roles.
110
Bishop Fox @bishopfox.bsky.social · 02/09/2026
Full advisory: bfx.social/4cqonCd
010
Bishop Fox @bishopfox.bsky.social · 02/09/2026
A request read timeout that's enabled, documented, and visible in the configuration isn't much help if it never applies. Our latest advisory covers a Traefik HTTP/3 vulnerability that could allow unauthenticated clients to tie up backend connections indefinitely.
110
Bishop Fox @bishopfox.bsky.social · 31/08/2026
Full episode now on YouTube: bfx.social/4zFzPDM
bfx.social
Block Out the Noise - Seth Art
Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.
010
Bishop Fox @bishopfox.bsky.social · 31/08/2026
AI can make you faster, but it can't replace good engineering. Former Fox and @datadoghq.com security researcher @Seth Art joins us to talk about building trustworthy tools, why testing still matters, and what AI changes (and doesn't) for developers.
110
Bishop Fox @bishopfox.bsky.social · 28/08/2026
Full research: bfx.social/4A2DQTd
010
Bishop Fox @bishopfox.bsky.social · 28/08/2026
Two critical vulnerabilities in Veeam Service Provider Console can be chained into unauthenticated remote code execution. Our researchers validated the attack chain, analyzed the patch, published indicators of compromise, and released a safe detection tool defenders can use today.
110