meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Tuesday, December 16th, 2025: Current React2Shell Example; SAML woes; MSMQ issues after patch;

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 16 December 2025

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Tuesday, December 16th, 2025: Current React2Shell Example; SAML woes; MSMQ issues after patch;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, December 16th, 2025 edition of the Sands Internet Storm centers, Stormcast.

0:12.9

My name is Johannes Ulrich, recording today from Jacksonville, Florida or virtually from Amsterdam, Netherlands.

0:20.8

And this episode is brought you by the sands.edu credit certificate program in cloud security.

0:28.3

And of course, React to Shell is still in the news, and I looked at what we have in current exploits in our honeypot.

0:34.5

There was one attempt that sort of was the most visible one in our honeypots, meaning it hit the most different honeypots.

0:43.9

Nothing fundamentally new here. It's of the usual malware distribution where they download a file, then mark as executable.

0:52.9

And this particular case, they actually kind of appear then to not launch the file

0:58.4

if I'm reading the code correctly.

1:00.5

So they may be missing a little piece here, and then use the standard ways to tuck away

1:07.0

an exploit or a piece of malware like this, like slash temp, slash deaf or slash

1:13.1

death shm, which of course the last one would be ephemeral and be deleted on each reboot.

1:20.8

Nothing too terribly exciting otherwise with React to Shell.

1:24.2

Yes, I saw the headline today that always means that exploitation pretty much has run its course.

1:29.3

And the headline was that Iranian actors are now taking part in scanning for React to Shell,

1:36.3

which of course, usually Iran, whenever they're mentioning news, it means that the exploit is old enough

1:41.4

where you probably don't have to worry about finding a lot of new

1:46.3

vulnerable systems that haven't been exploited yet.

1:50.4

Well, last week I talked about the new Samuel vulnerability in Ruby, which actually wasn't new

1:57.2

it was just an incomplete patch to a prior vulnerability.

2:07.2

We now have a great blog post by Port Swagger talking about what went wrong in this particular case and why there are some fundamental problems with Samel that makes it really difficult

2:12.7

to get it implemented correctly.

2:15.8

One problem with Ruby in particular is that within their SAML library, they're using

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.