Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.

Risky Business #818 -- React2Shell is a fun one

December 09, 2025 0:58:27 10.04 MB ( 46.08 MB less) Downloads: 0

In this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • There’s a CVSS 10/10 remote code exec in the React javascript server. JS server? U wot mate?
  • China is out popping shells with it
  • Linux adds support for PCIe bus encryption
  • Amnesty International says Intellexa can just TeamViewer into its customers’ surveillance systems
  • …and a Belgian murder suspect complains that GrapheneOS’s duress wipe feature failed him?

This week’s episode is sponsored by Kroll Cyber. Simon Onyons is Managing Director at Kroll’s Cyber and Data Resilience arm, and he discusses a problem near to many of our hearts. Just how do you explain cyber risk to the board?

This episode is also available on Youtube.

Show notes