Risky Business #818 -- React2Shell Is a Fun One
Cybersecurity

Risky Business

Risky Business #818 -- React2Shell Is a Fun One

Risky BusinessDec 10, 2025

AI Summary

Patrick Gray and Adam Boileau unpack a week of cyber news, led by the shocking CVSS 10/10 React2Shell vulnerability that lets attackers execute code on React JavaScript servers—a flaw quickly weaponized by Chinese APT groups. They also note Linux’s new PCIe bus encryption for cloud servers, Amnesty International’s expose of Intellexa’s spyware access, and a Belgian murder suspect’s claim that GrapheneOS’s duress‑wipe failed. The episode’s sponsor, Kroll Cyber, contributes a segment on translating cyber risk into board‑level language.

Episode Description

In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

There’s a CVSS 10/10 remote code exec in the React javascript server. JS server? U wot mate?

China is out popping shells with it

Linux adds support for PCIe bus encryption

Amnesty International says Intellexa can just TeamViewer into its customers’ surveillance systems

…and a Belgian murder suspect complains that GrapheneOS’s duress wipe feature failed him?

This week’s episode is sponsored by Kroll Cyber. Simon Onyons is Managing Director at Kroll’s Cyber and Data Resilience arm, and he discusses a problem near to many of our hearts. Just how do you explain cyber risk to the board?

This episode is also available on Youtube.

Show notes

Risky Bulletin: APTs go after the React2Shell vulnerability within hours - Risky Business Media

Guillermo Rauch on X: "React2Shell" / X

React2Shell-CVE-2025-55182-original-poc/README.md at main · lachlan2k/React2Shell-CVE-2025-55182-original-poc · GitHub

Hydrogen: Shopify’s headless commerce framework

Researchers track dozens of organizations affected by React2Shell compromises tied to China’s MSS | The Record from Recorded Future News

Unveiling WARP PANDA: A New Sophisticated China-Nexus Adversary

Three hacking groups, two vulnerabilities and all eyes on China | The Record from Recorded Future News

Risky Bulletin: Linux adds PCIe encryption to help secure cloud servers

Sean Plankey nomination to lead CISA appears to be over after Thursday vote | CyberScoop

🕳 on X: "This guy is complaining that GrapheneOS “failed him”. Showing a Belgian 🇧🇪 police request for an interrogation regarding premeditated murder (as a suspect)." / X

Sanctioned spyware maker Intellexa had direct access to government espionage victims, researchers say | TechCrunch

To Catch a Predator: Leak exposes the internal operations of Intellexa’s mercenary spyware - Amnesty International Security Lab

Is ransomware finally on the decline? Treasury data offers cautious hope | CyberScoop

UK cyber agency warns LLMs will always be vulnerable to prompt injection | CyberScoop

In comedy of errors, men accused of wiping gov databases turned to an AI tool - Ars Technica

Show Notes

In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • There’s a CVSS 10/10 remote code exec in the React javascript server. JS server? U wot mate?

  • China is out popping shells with it

  • Linux adds support for PCIe bus encryption

  • Amnesty International says Intellexa can just TeamViewer into its customers’ surveillance systems

  • …and a Belgian murder suspect complains that GrapheneOS’s duress wipe feature failed him?

This week’s episode is sponsored by Kroll Cyber. Simon Onyons is Managing Director at Kroll’s Cyber and Data Resilience arm, and he discusses a problem near to many of our hearts. Just how do you explain cyber risk to the board?

This episode is also available on Youtube.

Show notes

Comments

Want to join the conversation?

Loading comments...