What happens when the attacker succeeds anyway?
@AletheDenis explores why social engineering is ultimately a control design problem and why awareness training alone isn’t enough.
PCI DSS scope isn’t limited to traditional network segments anymore.
Now cloud infrastructure, SaaS platforms, IAM, and CI/CD pipelines can all play a role in an attack path to the CDE.
Derek Rush breaks down how Bishop Fox approaches modern PCI internal penetration testing.
Ever wondered how security researchers go from a physical device to root access?
Join Bishop Fox consultants Marco Sanchez and Abdel Bolivar for a hands-on introduction to hardware hacking. Learn about debug interfaces, firmware extraction, embedded systems, and more.
Available in English and Spanish
Researchers built an AI-powered worm that compromised nearly 75% of a simulated corporate network.
Shad Malloy’s response?
The real world is weird.
Broken workflows, strange systems, and Jackie from Accounting might be stronger defenses than people realize.
Happening today at 2 p.m. ET:
You can’t prevent every employee from being fooled.
You can (and should!) design systems so that one mistake doesn’t become a breach.
Join @AletheDenis as she explores why social engineering is ultimately a control design problem and what organizations can do to reduce risk in a world of phishing, vishing, deepfakes, and AI-enabled deception.
Sparkplug B is widely used across ICS and SCADA environments.
Until now, there wasn’t a publicly available security fuzzer built for it.
New research from David Colón and Shad Malloy explores how they built a Sparkplug B fuzzer covering all 9 message types, all 19 data types, and 87+ protocol field paths with some help from AI.
What are Red Team Arts & Crafts?
Honestly, it can be a pretty important part of a successful red team engagement!
@BrandonKovacs on how a bit of craftiness saved the day on one of his.
Heading to @BSidesSATX next weekend?
The Bishop Fox team will be there and we’d love to connect.
Come talk offensive security, AI, Red Teaming, research, career growth, or whatever interesting problem you’re working on.
Do red teamers need to know how to code?
Leron Gray tackles that question in the latest Red Team episode of Initial Access.
And in the age of AI-assisted development, the answer may be changing.
We’re heading to @RBLN26!
Catch Wes Wright’s talk, Getting the Most Out of Security Testing: A Hacker’s Perspective, and stop by to talk red teaming, AI, attack paths, and offensive security with the Bishop Fox team.
We also have a limited number of tickets available. Reach out if you’d like one!