Navigated to Risky Business #818 -- React2Shell is a fun one

Risky Business #818 -- React2Shell is a fun one

Dec 10, 2025
58 mins

View Transcript

Episode Description

In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • There’s a CVSS 10/10 remote code exec in the React javascript server. JS server? U wot mate?
  • China is out popping shells with it
  • Linux adds support for PCIe bus encryption
  • Amnesty International says Intellexa can just TeamViewer into its customers’ surveillance systems
  • …and a Belgian murder suspect complains that GrapheneOS’s duress wipe feature failed him?

This week’s episode is sponsored by Kroll Cyber. Simon Onyons is Managing Director at Kroll’s Cyber and Data Resilience arm, and he discusses a problem near to many of our hearts. Just how do you explain cyber risk to the board?

This episode is also available on Youtube.

Show notes

See all episodes

Never lose your place, on any device

Create a free account to sync, back up, and get personal recommendations.