Abstract cybersecurity illustration featuring servers, network nodes, and stylized attack indicators representing penetration testing and threat activity.

Offensive
Security Blog

Expert insights on offensive security, AI vulnerabilities, and emerging threats from Bishop Fox's leading security researchers and penetration testers.

Loading results
Technical Research

One Port to Root: Weaponizing Check Point Management CVE-2026-93616

One Port to Root: Weaponizing Check Point Management CVE-2026-93616

Oct 1, 2026

An unauthenticated attacker who can reach TCP 19009 on a Check Point management server can take it over completely. Bishop Fox reproduced the full root RCE chain on R81.10 and R82.10, breaks down all three vulnerabilities the patch actually closes, and shares a safe detection tool for defenders.

By Jon Williams, Threat Enablement & Analysis Team

Industry

Separating Signal from Slop: Triaging CVEs in the Age of AI Security Research

Separating Signal from Slop: Triaging CVEs in the Age of AI Security Research

Sep 30, 2026

AI-assisted research is flooding the CVE pipeline with bugs that score critical but depend on configurations almost nobody runs. Bishop Fox tested four high-profile Nginx CVEs in the lab, measured real-world prevalence, and explains how to separate actual risk from well-marketed noise.

By Nate Robb, Threat Enablement & Analysis Team

Advisory

Zilliz / Attu | 2.6.5

Zilliz / Attu | 2.6.5

Sep 29, 2026

Two vulnerabilities in Zilliz Attu 2.6.5 chain into something serious. Missing authentication lets anyone proxy requests unauthenticated, and a regex bypass defeats the private IP block. Bishop Fox turned both into full Kubernetes namespace takeover in a cloud deployment. Update to 3.0.0 now.

By Bishop Fox

Technical Research

Master Key Included: Detecting SolarWinds ARM CVE-2026-28326

Master Key Included: Detecting SolarWinds ARM CVE-2026-28326

Sep 25, 2026

A hardcoded authentication secret ships with every SolarWinds Access Rights Manager install, and reaching TCP 55555 is enough to hit a .NET deserialization sink. Bishop Fox confirmed SYSTEM-level code execution, breaks down the root cause, and shares a safe detection tool for defenders.

By Jon Williams, Threat Enablement & Analysis Team

Technical Research

Unified Code, Unified Risks: Uncovering Vulnerabilities in .NET MAUI Applications

Unified Code, Unified Risks: Uncovering Vulnerabilities in .NET MAUI Applications

Sep 24, 2026

.NET MAUI lets developers write once and ship to both platforms. From an attacker's perspective, that means reverse-engineer once and break everywhere. This post walks through extracting readable assemblies from MAUI apps and the high-impact vulnerability patterns that consistently appear.

By Carlos Yanez

Technical Research

MikroTrick: Inside the RouterOS Takeover Chain

MikroTrick: Inside the RouterOS Takeover Chain

Sep 17, 2026

Attackers were exploiting MikroTik routers before fixes went public. Bishop Fox reproduced the full unauthenticated takeover chain, found persistence artifacts on real compromised devices, and breaks down what defenders need to investigate beyond patching to confirm they are actually clean.

By Emilio Gallegos

Technical Research

CVE-2026-82329: Unauthenticated Administrative Access in JFrog Artifactory via an Empty Cluster Join Key

CVE-2026-82329: Unauthenticated Administrative Access in JFrog Artifactory via an Empty Cluster Join Key

Sep 11, 2026

A misconfigured cluster join key in JFrog Artifactory's default install lets unauthenticated attackers mint a permanent admin token in one request. Bishop Fox reproduced the full chain, confirmed in-the-wild exploitation, and shares a non-invasive detection check and remediation guidance.

By Nate Robb, Threat Enablement & Analysis Team

Technical Research

Mind the Config: Detecting and Weaponizing NetScaler CVE-2026-19490

Mind the Config: Detecting and Weaponizing NetScaler CVE-2026-19490

Sep 10, 2026

A single unauthenticated request bypasses authentication on NetScaler Gateway and AAA virtual servers. Whether that means a dead-end session, a proxy into the internal network, or root on the appliance depends entirely on configuration. Bishop Fox maps every branch and shares a safe detection tool.

By Jon Williams, Threat Enablement & Analysis Team

Technical Research

Signature Optional - Analysis of CVE-2026-28323

Signature Optional - Analysis of CVE-2026-28323

Sep 3, 2026

SolarWinds Web Help Desk treated SAML signature verification as optional and skipped every other validation the spec requires. Bishop Fox confirmed the full exploit end to end: one forged POST request, no credentials, full session takeover. Here is the root cause, the fix, and how to detect it.

By Ronan Kervella, Threat Enablement & Analysis Team

Advisory

Traefik | Version Through 3.7.11

Traefik | Version Through 3.7.11

Aug 31, 2026

Traefik's request read timeout is enabled by default and documented without exception, but it has never applied to HTTP/3. Bishop Fox confirmed the gap across four years of releases, measured it against the backend, and reported it to the vendor, who shipped a fix within twelve days.

By Shad Malloy

Technical Research

A GUID is Not a Credential: Unauthenticated RCE in Veeam Service Provider Console

A GUID is Not a Credential: Unauthenticated RCE in Veeam Service Provider Console

Aug 26, 2026

Two critical vulnerabilities in Veeam Service Provider Console chain into unauthenticated remote code execution on the management server sitting above every tenant's backups. Bishop Fox confirmed the full chain end to end, breaks down both root causes, and shares a safe detection tool and IOCs.

By Jon Williams, Ronan Kervella, Threat Enablement & Analysis Team

Technical Research

No Crash Required: Verifying the Citrix NetScaler SAML Patch for CVE-2026-8452

No Crash Required: Verifying the Citrix NetScaler SAML Patch for CVE-2026-8452

Aug 21, 2026

CVE-2026-8452 lets an unauthenticated attacker corrupt memory in Citrix NetScaler's SAML parser with a single request, potentially leading to remote code execution. Bishop Fox breaks down the patch, how to safely verify it across a fleet, and what exploitation actually looks like in the logs.

By Jon Williams, Threat Enablement & Analysis Team

Industry

CTEM 101: Moving From Spreadsheets to Continuous Risk Reduction

CTEM 101: Moving From Spreadsheets to Continuous Risk Reduction

Aug 20, 2026

Traditional vulnerability management was built for a smaller, slower problem than most teams face today. This post breaks down CTEM, why it exists, how its five stages work, and what it actually takes to move from a reactive pile of findings to a continuous, prioritized risk reduction program.

By Ori Zigindere

Technical Research

Critical SQL Injection in Metabase via Password Reset: CVE-2026-72898

Critical SQL Injection in Metabase via Password Reset: CVE-2026-72898

Aug 11, 2026

Immediate action is advised for all organizations running self-hosted Metabase. A critical, unauthenticated SQL injection vulnerability has been disclosed in Metabase's password reset functionality, and Metabase has confirmed active exploitation in the wild.

By Threat Enablement & Analysis Team

Advisory

Python Software Foundation - Python 3.11.0a3 to 3.15.0b2

Python Software Foundation - Python 3.11.0a3 to 3.15.0b2

Aug 5, 2026

Bishop Fox discovered a privilege escalation vulnerability in Python for Windows affecting versions 3.11.0a3 through 3.15.0b2. A low-privilege user can plant malicious files and wait for a privileged account to run the interpreter, inheriting that account's elevated access. Patches are available.

By Jake Yamaki

Industry

What Security Leaders Think About Frontier AI Models: Firsthand of Mythos

What Security Leaders Think About Frontier AI Models: Firsthand of Mythos

Jul 31, 2026

Frontier AI models are raising the ceiling for skilled attackers and lowering the bar for everyone else. Leaders from Vista Equity, Cisco, and Bishop Fox share what that shift looks like in practice, how the existing security stack needs to change, and how long defenders will stay at a disadvantage.

By Bishop Fox Researchers

Technical Research

A Millisecond of Predictability: Why CVE-2026-11374 Is Hard to Exploit

A Millisecond of Predictability: Why CVE-2026-11374 Is Hard to Exploit

Jul 21, 2026

ManageEngine's SSO ticket was just the millisecond wall-clock time at login, making unauthenticated account takeover theoretically possible. Bishop Fox confirmed the exploit end to end and breaks down why blind exploitation is still impractical and what defenders should do about it.

By Jon Williams, Bishop Fox Researchers

Technical Research

Using MCP Agents for Penetration Testing

Using MCP Agents for Penetration Testing

Jul 17, 2026

AI agent harnesses are changing how penetration tests get executed. Bishop Fox used MCP agents across external, application, and cloud testing to surface two information leaks totaling over 12 million records in hours rather than days. Here is how the approach works and where it makes sense to use.

By Derek Rush

Technical Research

Introducing snowpick: Testing ServiceNow for Public Data Exposure

Introducing snowpick: Testing ServiceNow for Public Data Exposure

Jul 14, 2026

ServiceNow portals can expose backend records through public widgets and API endpoints even when the visible portal looks locked down. Bishop Fox built snowpick to test both surfaces systematically, and across 166 authorized assessments, nearly a third of instances returned data they shouldn't have.

By Emilio Gallegos

Technical Research

Cracking Firmware with Claude: Senior-Level Skill, Junior-Level Autonomy

Cracking Firmware with Claude: Senior-Level Skill, Junior-Level Autonomy

Jul 8, 2026

A senior Bishop Fox researcher once cracked SonicWall's proprietary firmware encryption by hand. We gave Claude the same problem, two artifacts, one instruction, and mostly got out of the way. What happened next reveals something important about where AI-assisted security research is heading.

By Jon Williams

Technical Research

On Favicons: From Browser Icons to Attack Surface Intelligence

On Favicons: From Browser Icons to Attack Surface Intelligence

Jul 2, 2026

Favicons are small, static, and rarely changed, which makes them a surprisingly durable fingerprint for identifying software across the internet. Bishop Fox built an AI-assisted pipeline to hash and enrich them at scale, and this post shares the methodology, the dataset, and why it matters.

By Aaron Ringo

Technical Research

AI Finds Vulnerabilities. Security Experts Find Impact.

AI Finds Vulnerabilities. Security Experts Find Impact.

Jun 24, 2026

AI got a security consultant 80% of the way through a real web application assessment. The other 20% was where the actual security work happened. This walkthrough shows where AI delivered, where it produced confident but impossible explanations, and why human judgment still drives real findings.

By Alberto Marroquin

Advisory

Shynet | VERSION 0.13.1

Shynet | VERSION 0.13.1

Jun 18, 2026

The following document describes identified vulnerabilities in the Shynet application version 0.13.1.

By Bishop Fox Researchers

Industry

The Smash-and-Grab Era

The Smash-and-Grab Era

Jun 17, 2026

We walk through three eras of cyber attacks and makes a troubling case that LLMs are removing the one constraint that kept attackers slow and detectable.

By Vinnie Liu