SANS Stormcast Tuesday, January 27th, 2026: PWD scanning; MSFT Office OOB Patch; Exposed Clawdbot (#)

SANS Stormcast Tuesday, January 27th, 2026: PWD scanning; MSFT Office OOB Patch; Exposed Clawdbot (#)

Author: Johannes B. Ullrich January 27, 2026 Duration: 5:50
SANS Stormcast Tuesday, January 27th, 2026: PWD scanning; MSFT Office OOB Patch; Exposed Clawdbot Scanning Webserver with "pwd" as a Starting Path Attackers are adding the output of the pwd command to their web scans. https://isc.sans.edu/diary/x/32654 Microsoft Office Security Feature Bypass Vulnerability CVE-2026-21509 Microsoft released an out-of-band patch for Office fixing a currently exploited vulnerability. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509 Exposed Clawdbot Instances Many users of the AI tool clawdbot expose instances without access control. https://x.com/theonejvo/status/2015485025266098536 keywords: clwadbot; office; patch; microsoft; webserver; scan; pwd

Each weekday morning, Johannes B. Ullrich provides a concise, actionable briefing on the shifting landscape of digital threats and defenses with SANS Internet Storm Center's Daily Network Security News Podcast. Think of it as your first cup of coffee for cybersecurity awareness-a focused, five-minute update that cuts through the noise. The content is shaped by real-time data and analysis from the SANS Internet Storm Center, enriched by questions and experiences shared directly from the community of professionals in the field. You’ll hear about emerging vulnerabilities, active exploits, and practical insights that are both late-breaking and genuinely educational, all delivered in a straightforward, no-frills manner. This podcast serves as a reliable filter, turning the overwhelming flow of security news into a clear, digestible summary that helps you understand current risks and start your day informed. It’s built on a foundation of shared knowledge, where listener contributions actively guide the discussion, making each episode a collaborative reflection of what matters right now in network security.
Author: Language: English Episodes: 100

SANS Internet Storm Center's Daily Network Security News Podcast
Podcast Episodes
9712 [not-audio_url] [/not-audio_url]

Duration: 5:00
SANS Stormcast Monday, November 24th, 2025: CSS Padding in Phishing; Oracle Identity Manager Scans Update; Use of CSS stuffing as an obfuscation technique? Phishing sites stuff their HTML with benign CSS code. This is li…

«1...678910