Listen "Adversarial Podcast S4E08 – Shai-Hulud worm strikes again, critical React vuln, CrowdStrike insider threat"
Episode Synopsis
00:00 Intro02:33 Shai Hulud 2.017:12 Max severity React vulnerability29:23 CrowdStrike catches insider feeding information to hackers46:24 Anthropic disruptes AI-orchestrated cyber campaign52:35 Uncertain economy takes effect on cyber teamsShai-Hulud 2.0 Aftermath: Trends, Victimology and ImpactResearchers report that Shai-Hulud 2.0 is an ongoing npm supply-chain worm that has compromised hundreds of packages and tens of thousands of GitHub repositories and siphoned secrets through CI/CD pipelines.Critical React Server Components Vulnerability CVE-2025-55182React vulnerability React Server Components (RSC) — tracked as CVE-2025-55182 — is a critical (CVSS 10.0) flaw that allows unauthenticated attackers to execute arbitrary code on servers just by sending a crafted HTTP request to vulnerable packages.CrowdStrike catches insider feeding information to hackersCrowdStrike caught an insider who had secretly shared screenshots of internal systems with hackers linked to Scattered Lapsus$ Hunters — though the company says no breach of its infrastructure occurred and no customer data was compromised.Comcast's 2025 Cybersecurity Threat ReportComcast Business’s 2025 Cybersecurity Threat Report finds that over the 12-month period ending May 31, 2025 the company recorded 34.6 billion cyber events — including 4.7 billion phishing attempts, 9.7 billion “drive-by” compromise attacks, 44,000 DDoS attacks, and 19.5 billion resource-development activities.Disrupting the first reported AI-orchestrated cyber espionage campaignAnthropic reports disrupting what it assesses to be the first large-scale, AI-orchestrated cyber espionage campaign, in which a Chinese state-linked group jailbroke Claude Code to autonomously conduct reconnaissance, exploit vulnerabilities, and exfiltrate data across dozens of global targets with minimal human involvement.Uncertain Economy Takes Toll on Cybersecurity TeamsEconomic uncertainty has hit corporate cyber operations: Artico Search and IANS Research report that cybersecurity budgets rose just 4% in 2025 (a five-year low), hiring growth slowed to 7% (down from 12% in 2024), and many security-teams are grappling with tighter budgets, fewer hires, and slower wage growth.Hosts:Jerry Perullo (Founder, https://adversarial.com/)Sounil Yu (Founder, https://www.knostic.ai/)Mario Duarte (Founder, stealth startup)Producer: Tillson Galloway (Founder, http://githoundexplore.com/)
More episodes of the podcast The Adversarial Podcast
Adversarial Podcast S4E07 – The password is "Louvre", AI ransomware, Nevada stands up to ransomware
11/11/2025
Adversarial Podcast S4E06 – F5 Breach, AWS Outage, Risk Management vs. Security Engineering
28/10/2025
Adversarial Podcast S4E03 – Fumbled NPM Attack, Entering the AI Browser Market, Salesloft breach
16/09/2025
ZARZA We are Zarza, the prestigious firm behind major projects in information technology.