Chinese hackers exploiting React2Shell bug impacting countless websites, Amazon researchers say
ID: 1e46f6c4-c36a-554b-a49b-359720361c5d
STIX ID: report--1e46f6c4-c36a-554b-a49b-359720361c5d
Feed Name: The Record from Recorded Future News
Threat Score
A critical (10/10) vulnerability, CVE-2025-55182 (“React2Shell”), in React Server Components—embedded in millions of products and many websites—is being actively scanned and exploited in the wild; Amazon and other security firms observed state-linked Chinese groups (Earth Lamia, Jackpot Panda) and other actors rapidly weaponizing public PoCs, prompting emergency fixes and advisories from vendors and CISA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
