SolarWinds ARM shipped with a shared authentication secret. An attacker who could reach TCP 55555 could bypass authentication and achieve SYSTEM-level RCE. @Jon Williams & the Bishop Fox TEA team reproduced CVE-2026-28326 and built a safe detector. The 8.8 score? It depends on your firewall.
Bishop Fox
@bishopfox.bsky.social
A leading provider of #offensivesecurity solutions & contributor to the #infosec community. #pentesting #hacking
¡Hoy tenemos taller en español! Samanta Aranda nos enseñará cómo aprovechar configuraciones incorrectas de CloudFormation para escalar privilegios en AWS. Un taller práctico sobre IAM, roles de servicio y rutas de ataque.
Who has the AI advantage right now? Evan Wolff says attackers. But as AI becomes embedded into everyday security tools, he expects defenders to start closing the gap.
Tomorrow at Ekoparty: iOS Game Hacking: From Zero to God Mode Luis De la Rosa & Steeven Rodríguez are taking over the Mobile Hacking Village with live reverse engineering, hooking, Infinite Coins, Speed Hacks and God Mode. Sala C2 2 PM ART https://bfx.social/4rR0oT6
Happening today: Weaponizing CloudFormation Samanta Aranda is going hands-on with how attackers can turn limited IAM permissions and misconfigured CloudFormation roles into paths to more access.
@Jon Williams gave an AI-powered vulnerability research lab raw UniFi firmware. It helped take the research all the way to a working unauthenticated exploit. This week at Ekoparty, Jon is demoing the takeover live and sharing where the AI worked and where it fell flat.
What does “no evidence of exploitation” mean when your telemetry couldn't distinguish legitimate access from abuse? Thomas Wilson breaks down the bigger lesson from the DC healthcare data exposure in the latest Initial Access.
http:// → blocked hTtp:// → private IP access Berenice Flores found two vulnerabilities in Zilliz Attu 2.6.5 that could be chained to reach internal services and, in a tested AWS EKS deployment, compromise the Kubernetes namespace. Upgrade to 3.0.0. https://bfx.social/4y26gdu
Happening next week: Weaponizing CloudFormation Samanta Aranda is going hands-on with how misconfigured CloudFormation execution roles can create paths to privilege escalation and persistence in AWS. Available on our site or in the Bishop Fox Discord server!
Finding more vulnerabilities doesn't help much if you can't really tell what matters. Ori Zigindere explains CTEM and how continuous scoping, prioritization, validation, and remediation can turn an endless backlog into actual risk reduction.
🔴 And we’re live! Vinnie Liu, Justin Greis, and Evan Wolff are talking AI security, identity risk, and the cybersecurity priorities shaping 2027. Join the conversation: https://bfx.social/4hlCdbT
Happening tomorrow at 2 PM ET. Vinnie Liu, Justin Greis, and Evan Wolff are getting together to talk AI security, identity risk, and the cybersecurity decisions organizations should be thinking about now as 2027 approaches.
Attackers can now build an AI team. Kendrick Urbaniak breaks down a campaign where different models were chosen for different jobs, using one for orchestration and others with looser restrictions for exploitation.
The questions that matter most in cybersecurity aren't always technical. Daniel Wallace of McKinsey explains why AI's shift to a non-deterministic world is changing how leaders think about risk, governance, and what actually deserves attention.
Most AWS attack paths begin with IAM permissions. At BSides Cleveland this Saturday, David Garlak explores what happens when you look beyond IAM and map attack paths across identity, network, and resource boundaries.
A secret is only useful if it actually exists. Nate Robb and the Bishop Fox Threat Enablement & Analysis Team break down how an empty cluster join key led to unauthenticated admin access in default JFrog Artifactory installs and how to safely detect it.
The security priorities for 2027 are already taking shape. Join Vinnie Liu, Justin Greis, and Evan Wolff on Sept. 29 for a discussion on AI security, identity risk, and the cybersecurity investments that matter heading into 2027.
“The map is not the territory.” A critical CVSS score tells you something. It doesn’t tell you everything. In the latest Initial Access, @Jon Williams talks about his NetScaler research and why defenders need to look beyond the advisory to understand what a CVE actually means for their environment.
A patched router can still belong to the attacker. Our latest RouterOS research reproduces the MikroTrick takeover chain and examines persistence found on real devices including privileged accounts, scripts, and scheduled tasks that can survive after logs are gone. Patch. Then investigate.
The conversation around AI is shifting from whether to use it to where human judgment still matters most. Bishop Fox CISO Christie Terrill shares why protecting time to think, building good governance, and knowing when to trust AI are becoming essential leadership skills.
Schedule update: Our Weaponizing CloudFormation workshops originally scheduled to start today have been rescheduled. Apologies for the last-minute change, and thanks for understanding.
The login screen should be a security boundary. But in vulnerable SolarWinds Web Help Desk versions, an attacker who knew a valid username could forge a SAML response and authenticate with a single HTTP request.
CloudFormation is supposed to automate deployments, but what happens when it has more permissions than you do? Next week, Samanta Aranda shows how attackers abuse misconfigured execution roles, iam:PassRole, and Lambda-backed Custom Resources to escalate privileges and establish persistence in AWS.
"I'd know if it was fake." Would you, though? @decius.bsky.social says most people underestimate how quickly AI-generated voice and video are improving. The next 12–18 months are going to change what we trust online.
CloudFormation can become an attack path when execution roles have more permissions than the user invoking them. On Sept. 15 (English) and Sept. 17 (Spanish), Samanta Aranda walks through real privilege escalation and persistence techniques using misconfigured CloudFormation execution roles.
A request read timeout that's enabled, documented, and visible in the configuration isn't much help if it never applies. Our latest advisory covers a Traefik HTTP/3 vulnerability that could allow unauthenticated clients to tie up backend connections indefinitely.
AI can make you faster, but it can't replace good engineering. Former Fox and @datadoghq.com security researcher @Seth Art joins us to talk about building trustworthy tools, why testing still matters, and what AI changes (and doesn't) for developers.
Two critical vulnerabilities in Veeam Service Provider Console can be chained into unauthenticated remote code execution. Our researchers validated the attack chain, analyzed the patch, published indicators of compromise, and released a safe detection tool defenders can use today.
Everyone's talking about AI.| Infolock Field CTO Kraig Faulkner says the real conversation should be about the data AI can access. We talk data security, AI guardrails, why "set it and forget it" doesn't work, and the shift from identities to entities.
CVE-2026-8452 is an unauthenticated heap overflow in Citrix NetScaler’s SAML handling. The interesting part: defenders can tell patched and unpatched systems apart externally without triggering the crash. @Jon Williams explains how and released the check.