Dan Petro helps the competitive Super Smash Bros. Melee community catch cheating by analyzing replay data for impossible inputs, illegal controllers, and hidden macros. If you're at @DEF CON, catch his talk at the Game Hacking Village.
Bishop Fox
@bishopfox.bsky.social
A leading provider of #offensivesecurity solutions & contributor to the #infosec community. #pentesting #hacking
Planning your @defcon.bsky.social schedule? Our team will be speaking across multiple villages with hands-on workshops, research, live demos, and panels covering cloud security, AI, red teaming, game hacking, and more. Swipe through to see where you can find us.
Going to @blackhatevents.bsky.social next week? Come see the Bishop Fox team at Booth 5200 in the AI Zone. We'll be showing live demos of AI-powered offensive security, talking research, and connecting with the community all week. See you there! https://bfx.social/44Ujc9o
How do you know a new vulnerability disclosure initiative like Gold Eagle is working? Full episode: bishopfox.com/podcasts/who...
🚨 We're live! Join Bishop Fox experts for The Prioritization Problem and learn why more findings don't always mean less risk. bishopfox.com/resources/pr...
The Prioritization Problem: Why More Findings Don’t Mean Less Risk
More findings don't mean less risk. Bishop Fox experts break down why prioritization has become the defining challenge for modern security programs.
bishopfox.com
Hollywood has made hackers pop culture icons. This Friday at San Diego Comic-Con, @alethe.bsky.social joins a panel exploring what movies, TV, and games get right (and wrong) about hacking, social engineering, and today's threat landscape. Read the full issue: bishopfox.com/events/san-d...
If everything is a priority, nothing is. Join Bishop Fox on July 23 for a conversation about why more findings don't automatically reduce risk and how offensive security helps identify what matters most.
🔴 Happening now! Join @alethe.bsky.social for a hands-on workshop on building pressure-proof pretexts that hold up when the unexpected happens. If you're interested in social engineering, this one's a must-see: bishopfox.com/resources/so...
New open-source tool: snowpick ServiceNow portals can expose backend data through public widgets and the Table REST API. snowpick helps security teams test for those exposures from an unauthenticated perspective and generates reproducible evidence for validation.
Happening this week. How do you build a pretext that doesn't fall apart the first time someone asks an unexpected question? Join @alethe.bsky.social for a practical workshop on creating social engineering pretexts that hold up under real-world pressure.
If your idea of a good day involves breaking things… We’re hiring! Come work with a team that spends its time researching vulnerabilities, building tools, and helping organizations solve difficult security problems. bishopfox.com/careers
The best pretexts don’t fall apart the first time someone asks an unexpected question. Join @alethe.bsky.social for a workshop on building pressure-proof pretexts for physical red team engagements.
Some adventures in LLM firmware cracking! bishopfox.com/blog/crackin...
Cracking Firmware with Claude: Senior-Level Skill, Junior-Level…
Bishop Fox gave Claude an encrypted SonicWall firmware image and minimal guidance. With light supervision, it reverse engineered the encryption end to end.
bishopfox.com
Get ready, @summerc0n.bsky.social kicks off tomorrow! If you’re in Brooklyn, catch Shad Malloy presenting: Sparkplugs, Mosquitos, and Robots: "Fuzzing the Protocol Running Half the Smart Factories on Earth"
“Remember when gamers became Bitcoin miners?” Sergio Villegas thinks AI could be headed down a similar path with specialized hardware becoming the next big differentiator. Agree or disagree? Full episode: bishopfox.com/podcasts/the...
Most people never think about favicons. Turns out they’re a surprisingly useful way to fingerprint software, find related infrastructure, and pivot across attack surfaces. Aaron Ringo explains the methodology and shares the AI-assisted workflow and dataset behind it: bishopfox.com/blog/on-favi...
When people hear “residential proxy,” they often assume someone’s device was hacked. Sometimes that’s true. Other times, people install proxy software themselves because it’s “free.” Kendrick Urbaniak breaks down how it works and why you should think twice before becoming someone else’s exit node.
“What do you get when you hand a protocol fuzzer to Claude Code?” You’ll find out at SummerCon. Shad Malloy is unveiling a new open-source Sparkplug B fuzzer and sharing what AI-assisted protocol research actually looks like: the wins, the frustrations, and a live demo on real hardware.
This was one of the more interesting stories we covered this week. Millions of Pokémon GO players contributed scan data to improve an AR game. Years later, that same data is part of a conversation about AI-powered navigation and military applications. Full episode: bishopfox.com/podcasts/the...
Ever wondered where hardware hackers start when they get a new device? This workshop covers the basics: identifying components, finding debug interfaces, extracting firmware, and understanding how embedded devices actually work. With Marco Sanchez and Abdel Bolivar.
Many organizations treat awareness training as the foundation of social engineering defense. @alethe.bsky.social makes the case that the bigger issue is what happens when deception works.
Many organizations think of PCI segmentation as a network problem while attackers often see it as an identity problem. In this post, Derek Rush explains how PCI DSS v4.0.1 has expanded what can fall in scope and why effective internal penetration testing needs to validate real attack paths.
Ever wondered how security researchers go from a physical device to root access? Join Bishop Fox consultants Marco Sanchez and Abdel Bolivar for a hands-on introduction to hardware hacking. Learn about debug interfaces, firmware extraction, and more. 🌎 Available in English and Spanish
Researchers built an AI-powered worm that compromised nearly 75% of a simulated corporate network. Shad Malloy’s response? The real world is weird. Broken workflows, strange systems, and Jackie from Accounting might be stronger defenses than people realize.
Happening today at 2 p.m. ET: You can’t prevent every employee from being fooled. Join @alethe.bsky.social as she explores why social engineering is ultimately a control design problem and what organizations can do to reduce risk in a world of phishing, vishing, deepfakes, and AI deception.
We’ll be at both RBLN East and BSides SATX this weekend. Wes Wright is speaking at RBLN East on getting more value from security testing through an attacker’s lens. If you’re attending either event, come say hi! We also have a few RBLN tickets available, reach out if interested.
The newest episode of Initial Access is all about Red Teaming! Our consultants share stories about some of the wildest engagements they've ever been on, like this:
We’ve spent years teaching users how to spot social engineering. What happens when the attacker succeeds anyway? @alethe.bsky.social looks at social engineering through a different lens.
Can you determine whether a PAN-OS GlobalProtect portal is vulnerable to CVE-2026-0265 from a single anonymous request? Turns out you can. New research from @br4inde4d.bsky.social, John Untz, and the Bishop Fox team breaks down the detection technique and releases an open-source checker.
Awesome to see the love for AIMap. What have you all been able to accomplish with it so far? 🤔
Hottest cybersecurity open-source tools of the month: May 2026 📖 Read more: www.helpnetsecurity.com/2026/05/28/h... #cybersecurity #cybersecuritynews #opensource #software @github.com @bishopfox.bsky.social @sandeepk.bsky.social @sonukapoor.bsky.social