meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Tuesday, July 21st, 2026: More Wordpress Details; HOLLOWGRAPH MSFT Calendar Abuse; Gitea Vulnerability

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9755 Ratings

🗓️ 21 July 2026

⏱️ 9 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Tuesday, July 21st, 2026: More Wordpress Details; HOLLOWGRAPH MSFT Calendar Abuse; Gitea Vulnerability

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, July 21st,

0:07.9

2006 edition of the Sands and then at Storms, Stormcast. My name is Johannes Ulrich,

0:15.0

recording today from Jacksonville, Florida. And this episode is brought you by the sands.edu graduate certificate program in

0:23.6

industrial control system security.

0:26.9

Well, yesterday I mentioned the WordPress vulnerability that hadn't exploit available and

0:34.0

yes, was already actively exploited.

0:36.7

Today I took the time to set up a vulnerable

0:40.0

WordPress instance and a reader also suggested or sent me some logs that they collected

0:48.5

about an actual exploit attempt using this WP2 shell vulnerability.

0:55.2

We now also got a CVE number for the vulnerability, 2026-630.

1:02.9

The initial advisory didn't include that yet.

1:05.5

And with WordPress extensions, we usually don't get CVE numbers.

1:12.8

But again, this is a vulnerability in WordPress core. And like I mentioned, I set up a vulnerable instance myself,

1:19.9

just going through the standard install instructions of WordPress without loading any special

1:26.9

extensions.

1:28.1

The instance was vulnerable.

1:30.2

So there's nothing you need to configure, enable or such, in order to be vulnerable.

1:36.3

As soon as the rest API is exposed, you are vulnerable.

1:42.0

Now, a couple of things about the exploit attempts that we have seen. They often

1:47.2

use a very obvious user agents, so that would be a first quick fix here to try to filter

1:52.5

these user agents, like the one that I wrote up here, used the actual CVE number as a user agent.

2:00.7

We also have things like WP to Shell Test. That's often... used the actual CVE number as a user agent.

...

Transcript will be available on the free plan in 21 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.