Quantcast
Channel: bishopfox.com
Browsing index pages (134 articles)
↧

CTEM 101: Moving From Spreadsheets to Continuous Risk Reduction

Traditional vulnerability management was built for a smaller, slower problem than most teams face today. This post breaks down CTEM, why it exists, how its five stages work, and what it actually takes...

View Article


What Security Leaders Think About Frontier AI Models: Firsthand of Mythos

Frontier AI models are raising the ceiling for skilled attackers and lowering the bar for everyone else. Leaders from Vista Equity, Cisco, and Bishop Fox share what that shift looks like in practice,...

View Article


Navigating Threats: Adopting Proactive Social Engineering and Network Testing...

Get insights from Bishop Fox experts on social engineering tactics, implementing technical controls, and the importance of internal network testing.

View Article

Strengthening Cybersecurity Defenses: Validating Incident Response Plans with...

In this blog, learn how Bishop Fox Red Team tabletop exercises help organizations test Incident Response plans against tactics, techniques, and procedures used by attackers.

View Article

Purple Teaming: Validating Cybersecurity Investments and Enhancing Efficiency

Learn how Purple Teaming brings together offensive and defensive strategies for a more comprehensive and impactful cybersecurity approach.

View Article


Healthcare: 2023 Insights from the Ponemon Institute

Get insights into offensive security trends in the healthcare sector with data from the Ponemon Institute’s 2023 State of Offensive Security Report.

View Article

Red Teaming: 2023 Insights from the Ponemon Institute

Learn why mature organizations turn to Red Teaming to improve cybersecurity resiliency.

View Article

A Millisecond of Predictability: Why CVE-2026-11374 Is Hard to Exploit

ManageEngine's SSO ticket was just the millisecond wall-clock time at login, making unauthenticated account takeover theoretically possible. Bishop Fox confirmed the exploit end to end and breaks down...

View Article


Introducing snowpick: Testing ServiceNow for Public Data Exposure

ServiceNow portals can expose backend records through public widgets and API endpoints even when the visible portal looks locked down. Bishop Fox built snowpick to test both surfaces systematically,...

View Article


Cracking Firmware with Claude: Senior-Level Skill, Junior-Level Autonomy

A senior Bishop Fox researcher once cracked SonicWall's proprietary firmware encryption by hand. We gave Claude the same problem, two artifacts, one instruction, and mostly got out of the way. What...

View Article

On Favicons: From Browser Icons to Attack Surface Intelligence

Favicons are small, static, and rarely changed, which makes them a surprisingly durable fingerprint for identifying software across the internet. Bishop Fox built an AI-assisted pipeline to hash and...

View Article

AI Finds Vulnerabilities. Security Experts Find Impact.

AI got a security consultant 80% of the way through a real web application assessment. The other 20% was where the actual security work happened. This walkthrough shows where AI delivered, where it...

View Article

The Smash-and-Grab Era

We walk through three eras of cyber attacks and makes a troubling case that LLMs are removing the one constraint that kept attackers slow and detectable.

View Article


Enabling Proper PCI Testing with Internal Penetration Tests

PCI DSS v4.0.1 made internal penetration testing more complex, bringing cloud infrastructure, SaaS apps, and build pipelines explicitly into scope. Derek Rush breaks down how to scope a compliant IPT,...

View Article

Mythos Doesn't Deploy Itself

AI is raising the ceiling for skilled researchers and flooding bug bounty programs with polished but inaccurate submissions at the same time. Both things are true, and the reconciling variable is the...

View Article


Introducing Joro: Using AI to Build Security Tooling

Bishop Fox is releasing Joro, a collaborative web exploitation framework built almost entirely with AI. From intercepting proxy to C2 integration, this post covers how it was built, what it does, and...

View Article

Azure Hacking: New Cloudfoxable Challenges

Cloudfoxable started as a hands-on AWS security training tool. Now it's expanding. Bishop Fox has launched the first set of Azure challenges, giving security professionals a safe, intentionally...

View Article


Introducing AIMap: Security Testing For AI Agent Infrastructure

Attackers can already find, connect to, and probe your exposed AI agent infrastructure. AIMap gives defenders that same visibility. Built by Bishop Fox, this open-source tool discovers, scores, and...

View Article

Understanding the CVE Ecosystem and NIST’s Changing Role

NIST just announced it's prioritizing CVE enrichment for government systems and deprioritizing everything else. For security teams that rely on NVD data, the gap is real. Here's what changed, why it's...

View Article

Anthropic’s Claude Mythos Preview: The AI Cybersecurity Inflection Point

AI just crossed a threshold. Anthropic’s Claude Mythos can discover and chain vulnerabilities at scale—faster than teams can remediate. What does this mean for your security program, your providers,...

View Article
Browsing index pages (134 articles)


Latest Images