meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Thursday, December 18th, 2025: More React2Shell; Donicwall and Cisco Patch; Updated Chrome Advisory

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 18 December 2025

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Thursday, December 18th, 2025: More React2Shell; Donicwall and Cisco Patch; Updated Chrome Advisory

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, December 18th, 2025 edition of the Sands Internet Storm Center's Stormcast.

0:12.5

My name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:17.4

And this episode is brought you by the Sands.edu bachelor's decree program in applied cyber security.

0:25.3

The React to Shellwall ability is the gift that keeps on giving in a sense that, well, we keep seeing new variations of the exploit.

0:34.7

What's happening now is that attackers probably have realized that the original exploits

0:40.7

well have been run against all available systems. So there is really diminishing returns in

0:47.0

scanning the internet yet again with the same exploit. And we do see attackers vary a little bit.

0:53.1

So for example, they are changing the URL that they're targeting.

0:58.5

We had this one that now looks for example for slash API and slash app and various variations of that.

1:05.3

While the initial wave really just looked for the index page, which usually works sort of in these simple not customized kind of

1:13.3

applications we also see them at the rc action header which shows that they're going a little

1:21.3

away from just looking for next.js which of course again was the initial target of a lot of the exploits,

1:29.4

but also looking for other reasons why the React server components may be installed

1:34.5

and may be reachable. As before, well, if you have still an unpatched, vulnerable system,

1:43.8

assume compromise, even if the initial exploits may not have necessary. still an unpatched warnable system, assume

1:44.4

compromise, even if the

1:46.2

initial exploits may not have

1:48.2

necessarily shown your system

1:50.1

as vulnerable. We now

1:51.8

definitely see attackers customizing

1:54.2

and maybe also understanding

1:55.5

the vulnerability a little bit better and

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.