Discover
Initial Access
Initial Access
Author: Bishop Fox
Subscribed: 0Played: 0Subscribe
Share
© 2026 Bishop Fox
Description
Bishop Fox offensive security researchers, experts, and hackers take a real look at the latest cybersecurity news headlines and have a straight take on them. The goal is simple: do you actually need to care about this, or is it just another variation of the same fundamental security problems we've been dealing with for years?
38 Episodes
Reverse
In this episode, we break down three security stories: CVE-2026-88779, a third exploited NetScaler zero-day labeled denial-of-service About 8 million Danish CPR records stolen through a company's lawful access Google pausing its OSS VRP after a flood of invalid AI-generated reports Plus, we sit down with Andrew Crotty of the Ginger Hacker Initiative to talk about how newcomers actually break into cybersecurity in 2026, from choosing a path to building a resume that gets past the first screen. We also cover Bishop Fox research on how the AI attack surface extends across your full stack and what offensive testing reveals about healthcare security. Security Headlines: Citrix patches NetScaler SAML zero-day exploited in attacks, BleepingComputer Hackers steal 8 million citizens’ records from Danish government database, TechCrunch Google halts open-source bug bounty program amid AI spam surge, BleepingComputer Also mentioned: Events: No Hat 2026, HackMex 2026 Blog: Why the AI Attack Surface Extends Your Stack Guide: Healthcare Security: A Guide to Offensive Testing Andrew Crotty’s The Ginger Hacker Initiative Discord server. Join the conversation in the Bishop Fox Discord server and in the Bishop Fox subreddit.
In this episode, we break down four security stories: A ShinyHunters PeopleSoft WAF bypass that hinges on one URL-encoded character The arrest of an alleged ShinyHunters leader days before the group's FBI claim Nearly 400,000 DC Medicaid records left readable behind a public report OpenAI scrapping GPT-6.1 Astra over scope, authorization, and honesty We also cover Bishop Fox research on three practical risk questions: unauthenticated root RCE in Check Point management, Kubernetes namespace takeover in Zilliz Attu, and why an 85 percent jump in CVE disclosures does not automatically mean an 85 percent jump in real-world risk. Security Headlines: Google Warns of ShinyHunters' Fresh Oracle PeopleSoft Campaign, SecurityWeek Dutch police arrest suspected member of group that claimed FBI hack, BBC DC Health Agency Exposes 400,000 Beneficiary Records, SecurityWeek OpenAI scraps rollout of new AI model over safety concerns, BBC Also mentioned: Workshop: Weaponizing CloudFormation (available in English and Spanish) Events: SecureWorld Dallas 2026, VetsinTech NatSec + Space Innovation Summit 2026 Blog: One Port to Root: Weaponizing Check Point Management CVE-2026-93616 Blog: Zilliz / Attu | 2.6.5 Blog: Separating Signal from Slop: Triaging CVEs in the Age of AI Security Research Join the conversation in the Bishop Fox Discord server and in the Bishop Fox subreddit.
This episode breaks down:A zero-click Exchange Server RCE triggered by a Visio attachmentAI agents compromising online retailers for about $25 a targetShinyHunters' unverified claim that it breached the FBIOpenAI's six new misalignment disclosuresPlus, we sit-down with Bishop Fox's Emilio Gallegos on MikroTick, a RouterOS exploit chain attackers used before defenders knew it existed.Security Headlines:Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days, Security WeekAutonomous AI Agents are breaking into hundreds of Online Retailers for $25 a target in an ongoing campaign, Gambit SecurityFBI investigating claim hackers have stolen details of all its agents, BBCOpenAI Discloses Six New Incidents of ‘Concerning’ A.I. Behavior, The New York TimesAlso mentioned: Workshop: Weaponizing CloudFormation (available in English and Spanish) Virtual Session: AI & Cybersecurity Priorities for 2027: Executive ChatEvents: BSides Cleveland 2026, Ekoparty 2026, No Hat 2026, Wild West Hackin' Fest Deadwood 2026Blog: MikroTrick: Inside the RouteOS Takeover Chain Blog: Unified Code, Unified Risks: Uncovering Vulnerabilities in .NET MAUI ApplicationsBlog: Master Key Included: Detecting SolarWinds ARM CVE-2026-28326Join the conversation in the Bishop Fox Discord server and in the Bishop Fox subreddit.
This episode covers an AI agent fleet that compressed two weeks of red team work into ten hours, a two-CVE chain giving attackers full admin on MikroTik routers, and a fraudulent government request that walked Revolut's verification checks straight out the door, plus a sit-down with Bishop Fox's Jon Williams on a critical NetScaler auth bypass and the detection tool built to prove you're patched. Security Headlines: An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation, Unit 42 Your MikroTik Router May Already Be Compromised: Look for SSH User "-2", Security Affairs Revolut Confirms Customer Data Breach Through Fake Government Requests, TechCrunch Also mentioned: Workshop: Weaponizing CloudFormation (available in English and Spanish) Virtual Session: AI & Cybersecurity Priorities for 2027: Executive Chat Event: BSides Cleveland 2026 Blog: Mind the Config: Detecting and Weaponizing NetScaler CVE-2026-19490 Blog: MikroTrick: Inside the RouteOS Takeover Chain Join the conversation in the Bishop Fox Discord server and in the Bishop Fox subreddit.
Bishop Fox's Managed Security Services team returns with Sergio Villegas, Richard Brown, and Kendrick Urbaniak covering patch volume that no longer fits a normal cycle, threat intelligence with no real prioritization standard, and how to actually scope a vulnerability and intel program. Also mentioned: Workshop: Weaponizing CloudFormation Blog: Mind the Config: Detecting and Weaponizing NetScaler CVE-2026-19490 Blog: CVE-2026-82329: Unauthenticated Administrative Access in JFrog ArtifactoryJoin the conversation in the Bishop Fox Discord server and in the Bishop Fox subreddit.




