CTEM 101: Moving From Spreadsheets to Continuous Risk Reduction
Traditional vulnerability management was built for a smaller, slower problem than most teams face today. This post breaks down CTEM, why it exists, how its five stages work, and what it actually takes...
View ArticleWhat Security Leaders Think About Frontier AI Models: Firsthand of Mythos
Frontier AI models are raising the ceiling for skilled attackers and lowering the bar for everyone else. Leaders from Vista Equity, Cisco, and Bishop Fox share what that shift looks like in practice,...
View ArticleNavigating Threats: Adopting Proactive Social Engineering and Network Testing...
Get insights from Bishop Fox experts on social engineering tactics, implementing technical controls, and the importance of internal network testing.
View ArticleStrengthening Cybersecurity Defenses: Validating Incident Response Plans with...
In this blog, learn how Bishop Fox Red Team tabletop exercises help organizations test Incident Response plans against tactics, techniques, and procedures used by attackers.
View ArticlePurple Teaming: Validating Cybersecurity Investments and Enhancing Efficiency
Learn how Purple Teaming brings together offensive and defensive strategies for a more comprehensive and impactful cybersecurity approach.
View ArticleHealthcare: 2023 Insights from the Ponemon Institute
Get insights into offensive security trends in the healthcare sector with data from the Ponemon Institute’s 2023 State of Offensive Security Report.
View ArticleRed Teaming: 2023 Insights from the Ponemon Institute
Learn why mature organizations turn to Red Teaming to improve cybersecurity resiliency.
View ArticleA Millisecond of Predictability: Why CVE-2026-11374 Is Hard to Exploit
ManageEngine's SSO ticket was just the millisecond wall-clock time at login, making unauthenticated account takeover theoretically possible. Bishop Fox confirmed the exploit end to end and breaks down...
View ArticleIntroducing snowpick: Testing ServiceNow for Public Data Exposure
ServiceNow portals can expose backend records through public widgets and API endpoints even when the visible portal looks locked down. Bishop Fox built snowpick to test both surfaces systematically,...
View ArticleCracking Firmware with Claude: Senior-Level Skill, Junior-Level Autonomy
A senior Bishop Fox researcher once cracked SonicWall's proprietary firmware encryption by hand. We gave Claude the same problem, two artifacts, one instruction, and mostly got out of the way. What...
View ArticleOn Favicons: From Browser Icons to Attack Surface Intelligence
Favicons are small, static, and rarely changed, which makes them a surprisingly durable fingerprint for identifying software across the internet. Bishop Fox built an AI-assisted pipeline to hash and...
View ArticleAI Finds Vulnerabilities. Security Experts Find Impact.
AI got a security consultant 80% of the way through a real web application assessment. The other 20% was where the actual security work happened. This walkthrough shows where AI delivered, where it...
View ArticleThe Smash-and-Grab Era
We walk through three eras of cyber attacks and makes a troubling case that LLMs are removing the one constraint that kept attackers slow and detectable.
View ArticleEnabling Proper PCI Testing with Internal Penetration Tests
PCI DSS v4.0.1 made internal penetration testing more complex, bringing cloud infrastructure, SaaS apps, and build pipelines explicitly into scope. Derek Rush breaks down how to scope a compliant IPT,...
View ArticleMythos Doesn't Deploy Itself
AI is raising the ceiling for skilled researchers and flooding bug bounty programs with polished but inaccurate submissions at the same time. Both things are true, and the reconciling variable is the...
View ArticleIntroducing Joro: Using AI to Build Security Tooling
Bishop Fox is releasing Joro, a collaborative web exploitation framework built almost entirely with AI. From intercepting proxy to C2 integration, this post covers how it was built, what it does, and...
View ArticleAzure Hacking: New Cloudfoxable Challenges
Cloudfoxable started as a hands-on AWS security training tool. Now it's expanding. Bishop Fox has launched the first set of Azure challenges, giving security professionals a safe, intentionally...
View ArticleIntroducing AIMap: Security Testing For AI Agent Infrastructure
Attackers can already find, connect to, and probe your exposed AI agent infrastructure. AIMap gives defenders that same visibility. Built by Bishop Fox, this open-source tool discovers, scores, and...
View ArticleUnderstanding the CVE Ecosystem and NIST’s Changing Role
NIST just announced it's prioritizing CVE enrichment for government systems and deprioritizing everything else. For security teams that rely on NVD data, the gap is real. Here's what changed, why it's...
View ArticleAnthropic’s Claude Mythos Preview: The AI Cybersecurity Inflection Point
AI just crossed a threshold. Anthropic’s Claude Mythos can discover and chain vulnerabilities at scale—faster than teams can remediate. What does this mean for your security program, your providers,...
View Article