Bishop Fox offensive security researchers, experts, and hackers take a real look at the latest cybersecurity news headlines and have a straight take on them. The goal is simple: do you actually need to care about this, or is it just another variation of the same fundamental security problems we've been dealing with for years?
This episode covers a dark web marketplace selling 150+ million driver's license scans traced to one identity-verification vendor, McKesson's breach after a ShinyHunters vishing attack into Snowflake and Salesforce, Berlin's refusal to pay a ransomware group, and a suspected Iran-linked attack that knocked a UK power plant offline for days.
Security Headlines:
This episode covers an inaudible browser script fingerprinting AliExpress shoppers, AI-generated exploit scripts lowering the bar on Siemens PLC attacks, and researchers reviving an expired Visa card by rewriting one unsigned field, plus a Black Hat sit-down with InfoLock's Kraig Faulkner on why AI is forcing organizations to understand their own data.
Security Headlines:
A malicious MCP server tricks AI coding agents into leaking secrets, a three-year-old GeoServer bug resurfaces as a zero day, a hardware wallet maker's shipping partner exposes thousands of physical addresses, and a threat actor sells Fortune 500 org charts pulled from stolen Azure credentials.
Security Headlines:
This week's episode is different. No headlines, no CVEs. Just a live sit-down from Bishop Fox's RedTail meetup at DEF CON, with Bishop Fox's John Untz, Richard Brown, and Billy Giles, joined by Matt Bryant of OpenAI's Red Team, talking through what's signal vs. noise on the AI hype cycle, where AI actually earns its keep on offense, and what happens to the red-teaming pipeline if the entry-level rungs get automated away.
This is the debut episode from Bishop Fox's Managed Security Services team — not new headlines, but three stories the show already covered, revisited through the lens of what an operator actually does about them. First, JadePuffer, the ransomware Sysdig called the first fully autonomous, LLM-driven attack, with no human operator at any stage. Second, two OpenAI models that escaped an internal evaluation sandbox and breached H...
This episode covers a ChatGPT flaw that let one link spin up a fully authorized rogue AI agent, GitHub's public bug bounty cuts, Origin Energy's second breach in months, and 1,100+ AI lab employees asking Washington to help pace AI development, plus a sit-down with Bishop Fox's Dan Petro on catching cheaters in Super Smash Bros. Melee.
Security Headlines:
This episode breaks down OpenAI's own AI agent hacking into Hugging Face without human direction, an Android attack that hides commands in invisible screen text to hijack AI phone agents, and the White House's new Gold Eagle vulnerability clearinghouse, plus a sit-down with Bishop Fox's Emilio Gallegos on snowpick, his new opensource ServiceNow exposure scanner.
Security Headlines:
This week's episode is different. Bishop Fox Red Teamers Brandon Kovacs, Thomas Wilson, and Rob Antonucci talk through what attribution actually looks like when device-level telemetry breaks anonymity, what young attackers with real skills but zero tradecraft have in common, and how one credential reset becomes the master key to everything downstream.
Security Headlines:
This episode breaks down a Tenda router backdoor that turns out to be three years old, a phishing kit called EvilTokens that hides until a victim's browser builds it, and CISA turning Anthropic's Mythos model on the government's own code, plus a sit-down with IoT researcher Matt Evans on why Tenda keeps getting away with it.
Security Headlines:
· CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware, The Hacker News
· N...
This episode breaks down a Cisco flaw exploited within 24 hours of disclosure, a credential-harvesting campaign that hit 430,000+ FortiGate firewalls, and what Fable's restricted return and China's Tulongfeng mean for controlling offensive AI. Plus, a sit-down with Bishop Fox's Shad Malloy on building the first open-source Sparkplug B fuzzer for ICS environments.
Security Headlines:
This episode breaks down a public FIFA signup form wired straight to World Cup broadcast controls, an FFmpeg RCE buried in half your media apps, a SaaS breach cascading through delegated OAuth, and home routers conscripted into proxy infrastructure, plus a sit-down with Bishop Fox's Marco Sanchez on hardware hacking.
Security Headlines:
This episode explores what happens when the systems people trust quietly extend into domains they never agreed to. A Pokémon GO AR dataset trained a Visual Positioning System now adjacent to military drone navigation. A ServiceNow authentication flaw handed attackers read access to the operational core of enterprise IT. And the US government pulled two frontier AI models off the market over a jailbreak, with no established framewor...
This episode explores how the attack surface keeps expanding at every layer — from a single inverted kernel character enabling unauthenticated root, to AI assistants weaponized as system-wide IPC through notification injection, a Cisco SD-WAN zero-day giving attackers control of enterprise routing fabric, and the week's unavoidable elephant: whether Claude Fable V's guardrails actually hold.
This episode explores how attackers live in the gap between what a system can verify and what it settles for from forged GlobalProtect VPN sessions to an autonomous AI worm, a social-engineered Meta support bot, voice-phished Salesforce access, and hotel reservation hijacking.
This episode goes inside the Bishop Fox Red Team — exploring how AI accelerates custom payload evasion and social engineering at scale, what a chained network-to-physical breach looks like in practice, and why satellites and gas pumps are reachable from the public internet right now.
This episode explores how attackers exploit infrastructure that became load-bearing before anyone secured it from a malicious VS Code extension that compromised thousands of GitHub repositories and an actively exploited Exchange zero-day, to Cisco SD-WAN auth bypasses, AI chaining low-severity bugs into real attack paths, and AWS GovCloud credentials left exposed in a public repo.
This episode explores how modern development's trust assumptions keep failing in attackers' favor, from the first confirmed AI-written zero-day to a coordinated supply chain attack poisoning 518 million download paths, developer credential harvesting via rootkit, AWS SES abuse for phishing at scale, and thousands of vibe-coded apps leaking sensitive data in the open web.
This episode explores how every layer of the stack has become an attack surface — from a privilege-escalating Linux kernel flaw and a GitHub infrastructure RCE to a poisoned RubyGems supply chain, a trojanized vendor installer, and a ransomware hit on centralized education infrastructure.
This episode explores how access is being created, scaled, and kept with less friction, from a critical cPanel authentication bypass to AI-generated vulnerable code, AI-assisted attacks, persistent footholds in trusted systems, and stealthier data exfiltration.
This episode explores how access control is breaking down across AI systems, consumer apps, and vulnerability management, from leaked AI tooling and bypassed EU verification apps to actively exploited Windows zero-days and growing strain on the NVD.
If you've ever wanted to know about champagne, satanism, the Stonewall Uprising, chaos theory, LSD, El Nino, true crime and Rosa Parks, then look no further. Josh and Chuck have you covered.
Betrayal Weekly is back for a new season. Every Thursday, Betrayal Weekly shares first-hand accounts of broken trust, shocking deceptions, and the trail of destruction they leave behind. Hosted by Andrea Gunning, this weekly ongoing series digs into real-life stories of betrayal and the aftermath. From stories of double lives to dark discoveries, these are cautionary tales and accounts of resilience against all odds. From the producers of the critically acclaimed Betrayal series, Betrayal Weekly drops new episodes every Thursday. If you would like to share your story, you can reach out to the Betrayal Team by emailing them at betrayalpod@gmail.com and follow us on Instagram at @betrayalpod and @glasspodcasts. Please join our Substack for additional exclusive content, curated book recommendations, and community discussions. Sign up FREE by clicking this link Beyond Betrayal Substack. Join our community dedicated to truth, resilience, and healing. Your voice matters! Be a part of our Betrayal journey on Substack.
Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com
The official podcast of comedian Joe Rogan.
Former Bachelor Clayton Echard’s casual one-night fling turned into a paternity nightmare. When the news broke about the scandal, no one believed Clayton at first. He was a reality TV star, and an unpopular one at that. Clayton found himself trying to prove the truth, while trapped in a web of lies, manipulation, and threats. He would soon discover he was not the only one. At its core, this is a story about who you believe and why. It’s an epic battle that would take a group of strangers, citizen sleuths from across the world, to crack the case and finally hold someone accountable. New episodes of Love Trapped are released every Thursday, starting February 26th, 2026. If you would like to reach out to the Love Trapped team, email us at lovetrappedpod@gmail.com and follow along on Instagram @glasspodcasts.