Sep 26, 2026 · 1 hr 7 min · 11 segments
This episode breaks down: - A zero-click Exchange Server RCE triggered by a Visio attachment - AI agents compromising online retailers for about $25 a target - ShinyHunters' unverified claim that it…
It's CVE-2026-55007, an authenticated remote ex- code execution flaw in Exchange Server, where an attacker can trigger it by sending an email containing a specially crafted Visio attachment.
Uh, Exchange's content indexing engine processes the file automatically as part of a normal operation, so you don't have to click or anything.
Uh, their own advisory notes that reliable triggering depends on the server already being under sustained low memory pressure.
So that isn't typical day to day, but ZDI's Dustin Childs still ranked it ahead of the confirmed zero-days in priority.
Foundational identity and network services that are usually reachable without really interacting, touching a, a user at all.
I, I think, Sergio, did you mention this on one of your other podcasts where you were, uh, kinda going over the MSS team and, and what that, what that-
Yeah, we were discussing this last time we were talking about, uh, vulnerability intelligence in one of the MSS special episodes.
And one of the main discussions was, uh, spoiler, right? Like, we do these monthly specials, so stay tuned for those as well.
It's CVE-2026-55007, an authenticated remote ex- code execution flaw in Exchange Server, where an attacker can trigger it by sending an email containing a specially crafted Visio attachment.
Uh, Exchange's content indexing engine processes the file automatically as part of a normal operation, so you don't have to click or anything.
Uh, their own advisory notes that reliable triggering depends on the server already being under sustained low memory pressure.
So that isn't typical day to day, but ZDI's Dustin Childs still ranked it ahead of the confirmed zero-days in priority.
Foundational identity and network services that are usually reachable without really interacting, touching a, a user at all.
I, I think, Sergio, did you mention this on one of your other podcasts where you were, uh, kinda going over the MSS team and, and what that, what that-
Yeah, we were discussing this last time we were talking about, uh, vulnerability intelligence in one of the MSS special episodes.
And one of the main discussions was, uh, spoiler, right? Like, we do these monthly specials, so stay tuned for those as well.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.