Go offline with the Player FM app!
Legal corruption, React2Shell exploitation, dual-use AI risks
Manage episode 523913629 series 2416144
(Presented by ThreatLocker: Allow what you need. Block everything else by default, including ransomware and rogue code.)
Three Buddy Problem - Episode 76: On the show this week, Costin walks through how a single Romanian documentary kick-started nationwide protests, exposing how corruption can be perfectly legal when the law itself is gamed, and why this moment feels different, darker, and more consequential than past flare-ups.
Plus, news on the React-to-Shell exploitation wave overwhelming the internet, why patching is structurally hard, and how APTs and criminals are converging on the same fragile dependency chain. Along the way, they take aim at Microsoft’s shrinking transparency, the limits of vendor trust, and what it really means when defenders are told (again) to just patch and pray.
Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.
Links:
- Transcript (unedited, AI-generated)
- ThreatLocker : A security platform that prevents ransomware
- The Anatomy of a React2Shell Compromise (TLPBLACK)
- CVE-2025-55182 Analysis Report (GreyNoise)
- Exploitation of Critical Vulnerability in React Server Components
- PeerBlight Linux Backdoor Exploits React2Shell (Huntress)
- Patch Tuesday round-up (ZDI)
- How Two Hackers Went From Cisco Academy to Cisco CVEs
- Two Men Linked to China’s Salt Typhoon Hacker Group Likely Trained in a Cisco ‘Academy’
- OpenAI on dual-use AI risks
- Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite
- DOJ Actions to Combat Two Russian State-Sponsored Cyber Criminal Hacking Groups
- Microsoft paying bounties for vulns in third-party code
- Cybersecurity 2026 Predictions (SentinelLABS)
- Dakota Cary is in the "anti-China Chorus"
- Comparing AI Agents to Cybersecurity Professionals in Real-World Penetration Testing
- Automated React2Shell vulnerability patching is now available - Vercel
- Computer Olympiad enters new era as IITPSA hands over to Thinkst Applied Research
195 episodes
Manage episode 523913629 series 2416144
(Presented by ThreatLocker: Allow what you need. Block everything else by default, including ransomware and rogue code.)
Three Buddy Problem - Episode 76: On the show this week, Costin walks through how a single Romanian documentary kick-started nationwide protests, exposing how corruption can be perfectly legal when the law itself is gamed, and why this moment feels different, darker, and more consequential than past flare-ups.
Plus, news on the React-to-Shell exploitation wave overwhelming the internet, why patching is structurally hard, and how APTs and criminals are converging on the same fragile dependency chain. Along the way, they take aim at Microsoft’s shrinking transparency, the limits of vendor trust, and what it really means when defenders are told (again) to just patch and pray.
Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.
Links:
- Transcript (unedited, AI-generated)
- ThreatLocker : A security platform that prevents ransomware
- The Anatomy of a React2Shell Compromise (TLPBLACK)
- CVE-2025-55182 Analysis Report (GreyNoise)
- Exploitation of Critical Vulnerability in React Server Components
- PeerBlight Linux Backdoor Exploits React2Shell (Huntress)
- Patch Tuesday round-up (ZDI)
- How Two Hackers Went From Cisco Academy to Cisco CVEs
- Two Men Linked to China’s Salt Typhoon Hacker Group Likely Trained in a Cisco ‘Academy’
- OpenAI on dual-use AI risks
- Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite
- DOJ Actions to Combat Two Russian State-Sponsored Cyber Criminal Hacking Groups
- Microsoft paying bounties for vulns in third-party code
- Cybersecurity 2026 Predictions (SentinelLABS)
- Dakota Cary is in the "anti-China Chorus"
- Comparing AI Agents to Cybersecurity Professionals in Real-World Penetration Testing
- Automated React2Shell vulnerability patching is now available - Vercel
- Computer Olympiad enters new era as IITPSA hands over to Thinkst Applied Research
195 episodes
All episodes
×Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.