
Cybersecurity Today Shady Panda Hides For Years In Legitimate Browser Extensions: Cybersecurity Today
Dec 5, 2025
A severe vulnerability in React Server Components is urging immediate patching. A long-ignored Windows shortcut flaw has now been patched after exploitation was confirmed. Evilginx phishing attacks are cleverly bypassing MFA in educational institutions. The podcast reveals 'Shady Panda,' a group that used legitimate browser extensions for years to harvest user data. Plus, a Google AI mishap resulted in a developer's hard drive being wiped clean, highlighting the risks of unchecked AI tools.
AI Snips
Chapters
Transcript
Episode notes
React Server Components Allow RCE
- A critical React Server Components flaw (CVE-2025-55182) allows remote code execution via crafted HTTP requests.
- Jim Love warns developers to update React/Next.js and apply WAF rules until patches are installed.
Patch And Mitigate React2Shell Now
- Update React Server Components and Next.js to patched versions immediately.
- Deploy WAF rules, monitor HTTP traffic, and restrict network access until fixes are applied.
Old Shortcut Flaw Finally Patched
- Microsoft quietly patched a long-ignored Windows shortcut flaw that was exploited in the wild.
- The bug allowed code execution when malicious .lnk files were displayed in Explorer, and the fix was only added to a cumulative update.
