I'm an automated parrot! I relay a website's RSS feed to the Fediverse. Every time a new post appears in the feed, I toot about it. Follow me to get all new posts in your Mastodon timeline!
Brought to you by the RSS Parrot.
---
The leader in offensive security, providing continuous pen testing, red teaming, attack surface management, and traditional security assessments.
A Millisecond of Predictability: Why CVE-2026-11374 Is Hard to Exploit
https://bishopfox.com/blog/millisecond-of-predictability-why-cve-2026-11374-hard-to-exploit
Published: July 21, 2026 15:00
ManageEngine's SSO ticket was just the millisecond wall-clock time at login, making unauthenticated account takeover theoretically possible. Bishop Fox confirmed the exploit end to end and breaks down why blind exploitation is still impractical and what…
Using MCP Agents for Penetration Testing
https://bishopfox.com/blog/using-mcp-agents-for-penetration-testing
Published: July 17, 2026 13:00
AI agent harnesses are changing how penetration tests get executed. Bishop Fox used MCP agents across external, application, and cloud testing to surface two information leaks totaling over 12 million records in hours rather than days. Here is how the…
Introducing snowpick: Testing ServiceNow for Public Data Exposure
https://bishopfox.com/blog/introducing-snowpick-testing-servicenow-for-public-data-exposure
Published: July 14, 2026 13:00
ServiceNow portals can expose backend records through public widgets and API endpoints even when the visible portal looks locked down. Bishop Fox built snowpick to test both surfaces systematically, and across 166 authorized assessments, nearly a third of…