Cybersecurity Today

Shady Panda Hides For Years In Legitimate Browser Extensions: Cybersecurity Today

Dec 5, 2025
A severe vulnerability in React Server Components is urging immediate patching. A long-ignored Windows shortcut flaw has now been patched after exploitation was confirmed. Evilginx phishing attacks are cleverly bypassing MFA in educational institutions. The podcast reveals 'Shady Panda,' a group that used legitimate browser extensions for years to harvest user data. Plus, a Google AI mishap resulted in a developer's hard drive being wiped clean, highlighting the risks of unchecked AI tools.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

React Server Components Allow RCE

  • A critical React Server Components flaw (CVE-2025-55182) allows remote code execution via crafted HTTP requests.
  • Jim Love warns developers to update React/Next.js and apply WAF rules until patches are installed.
ADVICE

Patch And Mitigate React2Shell Now

  • Update React Server Components and Next.js to patched versions immediately.
  • Deploy WAF rules, monitor HTTP traffic, and restrict network access until fixes are applied.
INSIGHT

Old Shortcut Flaw Finally Patched

  • Microsoft quietly patched a long-ignored Windows shortcut flaw that was exploited in the wild.
  • The bug allowed code execution when malicious .lnk files were displayed in Explorer, and the fix was only added to a cumulative update.
Get the Snipd Podcast app to discover more snips from this episode
Get the app