Bishop Fox

@bishopfox.bsky.social

A leading provider of #offensivesecurity solutions & contributor to the #infosec community. #pentesting #hacking

Dan Petro helps the competitive Super Smash Bros. Melee community catch cheating by analyzing replay data for impossible inputs, illegal controllers, and hidden macros. If you're at @DEF CON, catch his talk at the Game Hacking Village.

Planning your @defcon.bsky.social schedule? Our team will be speaking across multiple villages with hands-on workshops, research, live demos, and panels covering cloud security, AI, red teaming, game hacking, and more. Swipe through to see where you can find us.

BildBildBildBild

Going to @blackhatevents.bsky.social next week? Come see the Bishop Fox team at Booth 5200 in the AI Zone. We'll be showing live demos of AI-powered offensive security, talking research, and connecting with the community all week. See you there! https://bfx.social/44Ujc9o

Bild

If everything is a priority, nothing is. Join Bishop Fox on July 23 for a conversation about why more findings don't automatically reduce risk and how offensive security helps identify what matters most.

Bild

New open-source tool: snowpick ServiceNow portals can expose backend data through public widgets and the Table REST API. snowpick helps security teams test for those exposures from an unauthenticated perspective and generates reproducible evidence for validation.

BildBildBildBild

When people hear “residential proxy,” they often assume someone’s device was hacked. Sometimes that’s true. Other times, people install proxy software themselves because it’s “free.” Kendrick Urbaniak breaks down how it works and why you should think twice before becoming someone else’s exit node.

“What do you get when you hand a protocol fuzzer to Claude Code?” You’ll find out at SummerCon. Shad Malloy is unveiling a new open-source Sparkplug B fuzzer and sharing what AI-assisted protocol research actually looks like: the wins, the frustrations, and a live demo on real hardware.

Ever wondered where hardware hackers start when they get a new device? This workshop covers the basics: identifying components, finding debug interfaces, extracting firmware, and understanding how embedded devices actually work. With Marco Sanchez and Abdel Bolivar.

Bild

Many organizations think of PCI segmentation as a network problem while attackers often see it as an identity problem. In this post, Derek Rush explains how PCI DSS v4.0.1 has expanded what can fall in scope and why effective internal penetration testing needs to validate real attack paths.

BildBildBildBild

Ever wondered how security researchers go from a physical device to root access? Join Bishop Fox consultants Marco Sanchez and Abdel Bolivar for a hands-on introduction to hardware hacking. Learn about debug interfaces, firmware extraction, and more. 🌎 Available in English and Spanish

Bild

Researchers built an AI-powered worm that compromised nearly 75% of a simulated corporate network. Shad Malloy’s response? The real world is weird. Broken workflows, strange systems, and Jackie from Accounting might be stronger defenses than people realize.

Happening today at 2 p.m. ET: You can’t prevent every employee from being fooled. Join @alethe.bsky.social as she explores why social engineering is ultimately a control design problem and what organizations can do to reduce risk in a world of phishing, vishing, deepfakes, and AI deception.

Bild

We’ll be at both RBLN East and BSides SATX this weekend. Wes Wright is speaking at RBLN East on getting more value from security testing through an attacker’s lens. If you’re attending either event, come say hi! We also have a few RBLN tickets available, reach out if interested.

BildBild

Can you determine whether a PAN-OS GlobalProtect portal is vulnerable to CVE-2026-0265 from a single anonymous request? Turns out you can. New research from @br4inde4d.bsky.social, John Untz, and the Bishop Fox team breaks down the detection technique and releases an open-source checker.

BildBildBildBild