Malicious npm packages, CISA budget cuts, hackers exploit React2Shell

Malicious npm packages, CISA budget cuts, hackers exploit React2Shell

Author: CISO Series April 6, 2026 Duration: 8:58

36 Malicious npm packages exploited to deploy persistent implants

Hundreds of millions to be cut from CISA in proposed budget

Hackers exploit React2Shell in automated credential theft campaign

Check out our show notes here: https://cisoseries.com/cybersecurity-news-malicious-npm-packages-cisa-budget-cuts-hackers-exploit-react2shell/

Huge thanks to our episode sponsor, Vanta

Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.


Keeping up with the constant flow of threats, breaches, and innovations in digital defense can feel like a full-time job. That’s where Cybersecurity Headlines comes in. Produced by the team at CISO Series, this daily audio briefing cuts through the noise to deliver the essential stories from the information security landscape. Each episode focuses on clarity and context, transforming complex technical developments and urgent news into digestible updates you can absorb during your morning routine or commute. You’ll hear a straightforward rundown of the day’s most significant events-whether it’s a newly discovered software vulnerability, a major regulatory shift, or analysis of a trending attack method. This podcast serves as your efficient, reliable starting point, ensuring you’re informed on the critical issues that impact professionals and organizations. For those wanting to explore a topic in greater depth, the conversation continues beyond the audio, with extended analysis and resources available from the creators. Tune in for a concise, no-frills update that helps you stay ahead in a field where yesterday’s news is already ancient history.
Author: Language: English Episodes: 100

Cybersecurity Headlines
Podcast Episodes
Adobe patches zero-day, Marimo flaw exploited, Venice flood threat [not-audio_url] [/not-audio_url]

Duration: 7:07
Adobe patches months-old Reader zero-day Critical Marimo flaw now under active exploitation Hackers claim control over Venice anti-flood pumps Get the show notes here: https://cisoseries.com/cybersecurity-news-adobe-patc…
ChipSoft popped, APT28 updates, CIA cyber espionage elevation [not-audio_url] [/not-audio_url]

Duration: 7:26
Ransomware knocks Dutch healthcare vendor offline APT28 is keeping busy CIA quietly elevated its cyber espionage division Check out our show notes here: https://cisoseries.com/cybersecurity-news-chipsoft-popped-apt28-upd…
Axios poisoned, TeamPCP details, Claude Code leaked [not-audio_url] [/not-audio_url]

Duration: 8:02
HTTP client introduces malicious dependency TeamPCP testing the open source supply chain Claude source code leaked Get the show notes here: https://cisoseries.com/cybersecurity-news-axios-poisoned-teampcp-details-claude-…