The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Threat Talks
Threat Talks artwork

React2Shell Explained

Threat Talks · 2026-03-24 · 15 min

0:00--:--

Topics in this episode

Zero TrustCyber SecurityHackON2IT

Episode notes

Log4j caught everyone off guard. React2Shell might be doing the same right now. Across thousands of React apps, exposure is already baked in - accelerated by vibe coding and shipped without scrutiny. In some cases, one request is all it takes. React2Shell turns that exposure into remote code execution in React and Next.js environments -triggered by a single HTTP POST request. In this episode of Threat Talks, host Rob Maas and SOC analyst Yuri Wit break down how React2Shell works, why it’s more serious than it looks, and what makes it so easy to exploit. The risk is significant, and what makes it worse is how little attention it’s getting. As developers increasingly rely on AI-generated code, applications are being shipped faster - but not always with full visibility into how components behave. That creates blind spots attackers can take advantage of, especially when serialization and deserialization flaws are involved. We cover how React2Shell works, how attackers exploit serialization and deserialization flaws, and what actions you need to take now to reduce risk.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • 93. Stop Wasting Payroll: How A $2,500 AI Automation Creates $80K in RevenueUnHacked · on Cyber Security88 / 100
  • The Weakest Link in a Global Life Sciences Company? People. With Dr. Kevin JonesCyber Leaders · on Zero Trust88 / 100
  • AI Security: Patricia Titus on Shadow AI, Non-Human Identities, and AI DefenseAI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop · on Zero Trust79 / 100
  • Can we protect ourselves from AI-powered cybercrime?Technology Now · on Zero Trust73 / 100
  • The Strategic Human Firewall as AI Impacts Regulations, Cyber Pros, and Employees - Robert Siciliano - BSW #453Security Weekly Podcast Network · on Zero Trust68 / 100
  • Absolute Security Joins Pax8 (EP 1039)Uncle Marv's IT Business Podcast · on Zero Trust63 / 100

More from Threat Talks

All episodes →
  • Why Do You Trust Your AI Agent?61 / 100
  • Mythos is not the AI Apocalypse80 / 100
  • What about Iran? One Word Document, Three Backdoors76 / 100
  • Europe Is Losing the Sea Cable Race76 / 100
  • Russia Cutting Cables?87 / 100
Explore the best B2B Engineering & DevTools podcasts →
All Threat Talks episodes →