
Initial Access
Claim This Podcastby Bishop Fox
Podcast Overview
<p>Bishop Fox offensive security researchers, experts, and hackers take a real look at the latest cybersecurity news headlines and have a straight take on them. The goal is simple: do you actually need to care about this, or is it just another variation of the same fundamental security problems we've been dealing with for years?</p>
Language
🇺🇲
Publishing Since
3/15/2026
3 verified contact emails on file for Initial Access
Pitch yourself as a guest, propose sponsorships, or reach out directly to the host.
Recent Episodes

July 20, 2026
Attribution and OpSec at Scale
<p>This week's episode is different. Bishop Fox Red Teamers Brandon Kovacs, Thomas Wilson, and Rob Antonucci talk through what attribution actually looks like when device-level telemetry breaks anonymity, what young attackers with real skills but zero tradecraft have in common, and how one credential reset becomes the master key to everything downstream. </p><p> </p><p><b>Security Headlines:</b> </p><ul><li><a rel="noopener noreferrer nofollow" href="https://www.zetter-zeroday.com/tracking-peter-stokes-and-the-com-allison-nixon-and-her-work-unmasking-cybercriminals/" target="_blank">Tracking Peter Stokes and The Com: Allison Nixon and Her Work Unmasking Cybercriminals,</a> Zero Day </li></ul><ul><li><a rel="noopener noreferrer nofollow" href="https://www.theregister.com/cyber-crime/2026/06/11/shinyhunters-raids-nottingham-uni-for-student-alumni-data/5253961" target="_blank">ShinyHunters Raids Nottingham Uni for Student, Alumni Data,</a> The Register </li></ul><p> </p><p>Join the conversation in the <a rel="noopener noreferrer nofollow" href="https://discord.gg/bishopfox" target="_blank">Bishop Fox Discord server</a> and in the new <a rel="noopener noreferrer nofollow" href="https://www.reddit.com/r/BishopFox/" target="_blank">Bishop Fox subreddit.</a> </p>

July 13, 2026
Old Backdoors, Ghost Phishing, and Borrowed AI
<p>This episode breaks down a Tenda router backdoor that turns out to be three years old, a phishing kit called EvilTokens that hides until a victim's browser builds it, and CISA turning Anthropic's Mythos model on the government's own code, plus a sit-down with IoT researcher Matt Evans on why Tenda keeps getting away with it.</p><p></p><p><b>Security Headlines:</b></p><p>· <a rel="noopener noreferrer nofollow" href="https://thehackernews.com/2026/07/certcc-warns-of-hidden-admin-backdoor.html" target="_blank">CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware</a>, The Hacker News</p><p>· <a rel="noopener noreferrer nofollow" href="https://thehackernews.com/2026/07/new-ghost-phishing-wave-is-breaking.html" target="_blank">New Ghost Phishing Wave Is Breaking Traditional Email Security</a>, The Hacker News</p><p>· <a rel="noopener noreferrer nofollow" href="https://www.securityweek.com/cisa-reportedly-using-anthropics-mythos-to-scan-government-software-for-flaws/" target="_blank">CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws</a>, Security Week</p><p> </p><p><b>Also mentioned:</b></p><p>· Blog: <a rel="noopener noreferrer nofollow" href="https://blog.uturn.dev/#/" target="_blank">Matt ‘uturn’ Evans</a></p><p>· Event: <a rel="noopener noreferrer nofollow" href="https://bishopfox.com/events/boston-security-meetup-july-2026" target="_blank">Boston Security Meetup 2026</a></p><p>· Workshop: <a rel="noopener noreferrer nofollow" href="https://bishopfox.com/resources/social-engineering-how-to-build-pressure-proof-pretexts" target="_blank">Social Engineering: How to Build Pressure-Proof Pretexts</a></p><p>· Virtual Session: <a rel="noopener noreferrer nofollow" href="https://bishopfox.com/resources/prioritization-problem-why-more-findings-dont-mean-less-risk" target="_blank">The Prioritization Problem: Why More Findings Don’t Mean Less Risk</a></p><p> </p><p>Join the conversation in the <a rel="noopener noreferrer nofollow" href="https://discord.gg/bishopfox" target="_blank">Bishop Fox Discord server</a> and in the new <a rel="noopener noreferrer nofollow" href="https://www.reddit.com/r/BishopFox/" target="_blank">Bishop Fox subreddit.</a></p>

July 6, 2026
Cisco Root Access, FortiBleed Credentials, Sparkplug Fuzzing, AI Arms Race
<p>This episode breaks down a Cisco flaw exploited within 24 hours of disclosure, a credential-harvesting campaign that hit 430,000+ FortiGate firewalls, and what Fable's restricted return and China's Tulongfeng mean for controlling offensive AI. Plus, a sit-down with Bishop Fox's Shad Malloy on building the first open-source Sparkplug B fuzzer for ICS environments. </p><p></p><p><b>Security Headlines:</b> </p><ul><li><a rel="noopener noreferrer nofollow" href="https://www.darkreading.com/cyberattacks-data-breaches/less-than-24-hours-attackers-weaponize-cisco-cucm-flaw" target="_blank">In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw</a>, Dark Reading </li></ul><ul><li><a rel="noopener noreferrer nofollow" href="https://www.scworld.com/news/fortibleed-campaign-steals-110m-credentials-from-fortigate-targets" target="_blank">FortiBleed campaign steals 110M credentials from FortiGate targets</a>, SC Media </li></ul><ul><li><a rel="noopener noreferrer nofollow" href="https://www.forbes.com/sites/craigsmith/2026/06/28/buckle-up-the-bad-guys-now-have-a-model-as-powerful-as-mythos/" target="_blank">Buckle Up: The Bad Guys Now Have A Model As Powerful As Mythos</a>, Forbes </li></ul><p> </p><p><b>Also Mentioned:</b> </p><ul><li>Research: <a rel="noopener noreferrer nofollow" href="https://bishopfox.com/blog/on-favicons-from-browser-icons-to-attack-surface-intelligence?utm_source=bf-email&utm_medium=email&utm_campaign=InitialAccessNewsletter" target="_blank">On Favicons: From Browser Icons to Attack Surface Intelligence</a> </li></ul><ul><li>Event: <a rel="noopener noreferrer nofollow" href="https://bishopfox.com/events/summercon-2026?utm_source=bf-email&utm_medium=email&utm_campaign=InitialAccessNewsletter" target="_blank">Summercon 2026 </a> </li></ul><ul><li>Event: <a rel="noopener noreferrer nofollow" href="https://bishopfox.com/events/san-diego-comic-con-2026?utm_source=bf-email&utm_medium=email&utm_campaign=InitialAccessNewsletter" target="_blank">San Diego Comic-Con 2026</a> </li></ul><p> </p><p>Join the conversation in the <a rel="noopener noreferrer nofollow" href="https://discord.gg/bishopfox?utm_source=bf-email&utm_medium=email&utm_campaign=InitialAccessNewsletter" target="_blank">Bishop Fox Discord Server.</a> </p>
26 total episodes available
Deep-dive analytics for Initial Access
Frequently asked questions
Have a different question and can't find the answer you're looking for? Reach out to our support team by sending us an email and we'll get back to you as soon as we can.
- What is Initial Access?
<p>Bishop Fox offensive security researchers, experts, and hackers take a real look at the latest cybersecurity news headlines and have a straight take on them. The goal is simple: do you actually need to care about this, or is it just another variation of the same fundamental security problems we've been dealing with for years?</p> - How often does this podcast release new episodes?
This podcast updates daily.
- Where can I listen to this podcast?
This podcast is available on 4 platforms including Apple Podcasts, Spotify, and more. You can also use the RSS feed directly.
- Does this podcast accept guests?
Yes, this podcast regularly features guests.
Legal Disclaimer
Pod Engine is not affiliated with, endorsed by, or officially connected with any of the podcasts displayed on this platform. We operate independently as a podcast discovery and analytics service.
All podcast artwork, thumbnails, and content displayed on this page are the property of their respective owners and are protected by applicable copyright laws. This includes, but is not limited to, podcast cover art, episode artwork, show descriptions, episode titles, transcripts, audio snippets, and any other content originating from the podcast creators or their licensors.
We display this content under fair use principles and/or implied license for the purpose of podcast discovery, information, and commentary. We make no claim of ownership over any podcast content, artwork, or related materials shown on this platform. All trademarks, service marks, and trade names are the property of their respective owners.
While we strive to ensure all content usage is properly authorized, if you are a rights holder and believe your content is being used inappropriately or without proper authorization, please contact us immediately at hey@podengine.ai for prompt review and appropriate action, which may include content removal or proper attribution.
By accessing and using this platform, you acknowledge and agree to respect all applicable copyright laws and intellectual property rights of content owners. Any unauthorized reproduction, distribution, or commercial use of the content displayed on this platform is strictly prohibited.
