CVE-2026-27886 is another CVE we researched/reproduced as part of @bishopfox's Emerging Threat process. Full admin account takeover in Strapi, ~20k internet-facing instances via Shodan.
Also, check out our detection tool: github.com/BishopFox/CVE-…
After not receiving a raise in the four years I’ve worked at BHIS they’ve now decided to reduce my pay by $40k after coming back from maternity leave and moving my role to solely pentesting. So I am looking for a new position effective immediately if anyone has any leads 😇
LiteLLM Proxy has a pre-auth SQL injection (CVE-2026-42208) I recently reproduced as part of @bishopfox's Emerging Threat process. Below is a technical analysis I put together with a safe detection payload that can be used to identify vulnerable deployments.
A failed login should not take 6 seconds.
Bishop Fox researchers reproduced CVE-2026-42208 in LiteLLM’s proxy. The attack requires no authentication, still returns HTTP 401 responses, and uses timing delays to extract sensitive data.
Observed in the wild roughly 36 hours after
We’re heading to @CactusCon 14! 🌵
Bishop Fox is sponsoring again this year, with talks from Dan Petro and Nate Robb on EDR evasion and real-world CVE prioritization. We’ll be around all weekend to talk Red Team tradecraft, research, and offensive security.
See you in Mesa!
@CactusCon Just a heads up, not seeing a "Notes to Organizer" section to include a talk outline on the session submission page. Tried throwing the outline at the end of the session description but hit the character limit.
Ever feel overwhelmed by the constant firehose of newly disclosed vulnerabilities? Check out my latest blog post where I outline the methodology our Threat Enablement team at Bishop Fox uses to cut through the noise:
bfx.social/3GcLIdz
Our Threat Enablement and Analysis team built a better way to cut through the noise. This is how we triage the firehose, turning chaos into action. By Senior Operator Nate Robb: bfx.social/45Ltri1
@_BalthazarBratt I just picked up the 16 inch M1 Pro a couple weeks ago and I love it. I'm impatient so I used this stock tracker app to jump on one when local apple store stock became available: worthbak.github.io/inventory-chec…
My team is hiring at @bishopfox! Come join the Adversarial Operations team for the Cosmos continuous attack surface testing platform.
bishopfox.com/jobs?gh_jid=36…
@jonathandata1 FYI: I could reproduce the Airdropped website auto accept only when both devices were signed in with the same Apple ID. When the Apple IDs were different (as would be the case in an attack) the victim device was prompted for permission to open the Airdropped website.
@AndrivetSeb I just stumbled upon your talk "The Security of MDM systems" from Hack in Paris 2013. Did you happen to publicly release the Java tool to decrypt passwords from identityconfig.xml files?
12K Followers 3K FollowingTrying to build systems of lasting value at https://t.co/JoR2nVEIRH. Previously CTO, Greywing (YC W21).
Chop wood carry water.
257 Followers 3K Followingjapes and general tomfoolery | red-teaming, hard-tech, synbio, anthropological history, linguistics, theories of life, etc | hmu at ping00 at protonmail dot com
69 Followers 43 FollowingSi disfrutas de juegos como Final Fantasy, Elden Ring, Monster Hunter, WoW, Guild Wars, Ashes of Creation y muchos más, este es tu perfil.
6 Followers 316 FollowingCyber Security student passionate about securing the digital world. Constantly learning and exploring the latest trends and technologies in the field.
9K Followers 495 FollowingI'm an engineer from Turkey, who is interested with biotechnology, computer science and digital gaming. Proud father of three little devils. A.K.A nukedx
27K Followers 1K FollowingI play with vulnerabilities and exploits. I used to be here on Twitter but now I'm here:
@[email protected]
https://t.co/hXggdAVkSQ
55K Followers 612 FollowingGrzegorz Niedziela - a hacker who documents his hacking journey by creating and curating the best content about bug bounty and offensive security.
12K Followers 3K FollowingTrying to build systems of lasting value at https://t.co/JoR2nVEIRH. Previously CTO, Greywing (YC W21).
Chop wood carry water.
89K Followers 18 FollowingTrendAI Zero Day Initiative™ (ZDI) is a program designed to reward security researchers for responsibly disclosing vulnerabilities.
9K Followers 495 FollowingI'm an engineer from Turkey, who is interested with biotechnology, computer science and digital gaming. Proud father of three little devils. A.K.A nukedx
587K Followers 9 FollowingSelect Committee to Investigate the January 6th Attack on the United States Capitol | Representative @BennieGThompson, Chairman
16K Followers 2K Following30 y/o Bug Bounty Hunter and Red Team Lead at Viettel Cyber Security.
Brand Ambassador @Hacker0x01 - Researcher Spotlight @Bugcrowd
259K Followers 8 FollowingBattlefield News, Dev Notes & Update Details. Content may change during Live Service.
ESRB rating: MATURE (17+) with Blood, Strong Language, and Violence.
38K Followers 183 FollowingNuclei uses a vast templating library to scan applications, cloud infrastructure, and networks to find and remediate vulnerabilities.
9K Followers 30 FollowingIP data built for scale. Get geolocation, privacy flags, carrier data & more.
IPinfo powers smarter decisions with the world’s most trusted IP data.
500K+ users