meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Wednesday, May 27th, 2026: Fake Claude Ads; SharePoint Vuln; Angular Vulnerabilities

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 27 May 2026

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Wednesday, May 27th, 2026: Fake Claude Ads; SharePoint Vuln; Angular Vulnerabilities

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, May 27, 2006 edition of the Sands Internet Storm Center's Stormcast.

0:12.8

My name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:17.8

And this episode is brought you by the sands.edu credit certificate program in penetration

0:23.1

testing and ethical hacking. Well, let's start today with a little bit of different spin on

0:28.9

AI. In this case, it's actually, well, not really AI at all. It's just a fake clot AI download

0:36.9

page that is being used by attackers to install the ECR stealer.

0:41.6

ECR stealer has been around for a while. It's sort of your standard info stealer stealing credentials and the like.

0:48.4

Often also consider sort of a malware as a service where attackers will install it and then basis of provide also the malware

0:55.8

and the credentials to the actual organization behind these attacks.

1:00.1

Now, the organizations that are sort of renting or buying ECR Steelers, they have then to find

1:06.7

a way for users to actually install it.

1:09.1

And in this particular case, well, they went with Google Ads,

1:13.2

the good old and proven method to trick users to install software.

1:19.3

When you're searching for Cloud, you may actually end up with a malicious code,

1:25.5

in this case with the InfoSteeler.

1:28.9

The download page, well, the domain looks nothing like Cloud,

1:31.8

like the one that Brad found here is Fairpoint29.com,

1:36.0

but there are likely many others, similar ones out there as well.

1:40.0

But the looking feel of the page, of course,

1:42.4

does match the official claw page.

1:45.7

So unless someone looks at the URL, they may not necessarily notice that they are on a malicious page.

1:53.3

And Microsoft actually surprised late last week with a surprise update for SharePoint.

...

Transcript will be available on the free plan in 19 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.