SANS Stormcast Wednesday, February 4th, 2026: Detecting OpenClaw; Synology telnetd Patch; More GlassWorm
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 4 February 2026
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Wednesday, February 4th, 2026 edition of the Sands Internet Storm Center's Stormcast. |
| 0:12.3 | My name is Johannes Ulrich, recording today from Jacksonville, Florida. |
| 0:17.2 | And this episode is brought you by the Sands.edu graduate certificate program in cyber defense operations. |
| 0:24.6 | Well, yesterday I talked a lot about open claw. So as a follow-up today, I wrote a quick post on how to detect, also a little bit on how to secure open claw. |
| 0:34.6 | The detection comes thanks to Gnostic. Gzik is a company that sort of works on |
| 0:40.3 | products to secure AI usage. There are two scripts that they published. One is fairly |
| 0:48.3 | straightforward. It just detects if open claw is installed by looking for common locations associated with open claw |
| 0:57.1 | like configuration files and the like and the binary itself. The second part is, I think, more |
| 1:04.8 | interesting, and that's open claw telemetry. And what this does is, if you have open claw |
| 1:10.4 | installed, open claw telemetry. And what this does is if you have open claw installed, open claw |
| 1:11.8 | telemetry will essentially log all the commands being executed by open claw, all the prompts, |
| 1:18.6 | and basically all the interactions that the user may have with open claw, but also interactions |
| 1:24.6 | open claw has with the various service it's connected to, |
| 1:28.2 | and these can then be collected via SISLog and other tools. |
| 1:31.4 | That's actually a plugin for OpenClaw itself. |
| 1:35.8 | So I highly recommend this if you are using OpenClaw, |
| 1:38.7 | because it will give you more transparency in what actually happens. |
| 1:43.3 | The remaining links are some links to open clause documentation |
| 1:48.1 | about how to secure it, how to run it in a sandbox, and then sort of some basic prompt hardening |
| 1:56.6 | tricks that you can use to likely make it more difficult to exploit any prompt injection. |
| 2:05.7 | Well, and remember, I think it was about a week or two ago where we had this critical flaw in TelnetD, |
| 2:12.2 | if it's installed with Inat D. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

