Legal corruption, React2Shell exploitation, dual-use AI risks episode artwork

EPISODE · Dec 11, 2025 · 2H 12M

Legal corruption, React2Shell exploitation, dual-use AI risks

from Three Buddy Problem · host Security Conversations

(Presented by ThreatLocker: Allow what you need. Block everything else by default, including ransomware and rogue code.) Three Buddy Problem - Episode 76: On the show this week, Costin walks through how a single Romanian documentary kick-started nationwide protests, exposing how corruption can be perfectly legal when the law itself is gamed, and why this moment feels different, darker, and more consequential than past flare-ups. Plus, news on the React-to-Shell exploitation wave overwhelming the internet, why patching is structurally hard, and how APTs and criminals are converging on the same fragile dependency chain. Along the way, they take aim at Microsoft’s shrinking transparency, the limits of vendor trust, and what it really means when defenders are told (again) to just patch and pray. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.

Episode metadata supplied by the publisher feed · Published Dec 11, 2025

Embed this episode

( Presented by ThreatLocker : Allow what you need. Block everything else by default, including ransomware and rogue code. ) Three Buddy Problem - Episode 76 : On the show this week, Costin walks through how a single Romanian documentary kick-started nationwide protests, exposing how corruption can be perfectly legal when the law itself is gamed, and why this moment feels different, darker, and more consequential than past flare-ups. Plus, news on the React-to-Shell exploitation wave overwhelming the internet, why patching is structurally hard, and how APTs and criminals are converging on the same fragile dependency chain. Along the way, they take aim at Microsoft’s shrinking transparency, the limits of vendor trust, and what it really means when defenders are told (again) to just patch and pray. Cast: Juan Andres Guerrero-Saade , Ryan Naraine and Costin Raiu . Links: Transcript (unedited, AI-generated) ThreatLocker : A security platform that prevents ransomware The Anatomy of a React2Shell Compromise (TLPBLACK) CVE-2025-55182 Analysis Report (GreyNoise) Exploitation of Critical Vulnerability in React Server Components PeerBlight Linux Backdoor Exploits React2Shell (Huntress) Patch Tuesday round-up (ZDI) How Two Hackers Went From Cisco Academy to Cisco CVEs Two Men Linked to China’s Salt Typhoon Hacker Group Likely Trained in a Cisco ‘Academy’ OpenAI on dual-use AI risks Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite DOJ Actions to Combat Two Russian State-Sponsored Cyber Criminal Hacking Groups Microsoft paying bounties for vulns in third-party code Cybersecurity 2026 Predictions (SentinelLABS) Dakota Cary is in the "anti-China Chorus" Comparing AI Agents to Cybersecurity Professionals in Real-World Penetration Testing Automated React2Shell vulnerability patching is now available - Vercel Computer Olympiad enters new era as IITPSA hands over to Thinkst Applied Research

Distinct summary based on available episode metadata or transcript content.

Ready to play

Legal corruption, React2Shell exploitation, dual-use AI risks

0:00 2:12:25

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Three Buddy Problem?

This episode is 2 hours and 12 minutes long.

When was this Three Buddy Problem episode published?

This episode was published on December 11, 2025.

Can I download this Three Buddy Problem episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!