Hackers Launched 8.1 Million Attack Sessions to React2Shell Vulnerability
ID: 6c215a07-1c4c-5479-a571-b1c33a6c705c
STIX ID: report--6c215a07-1c4c-5479-a571-b1c33a6c705c
Feed Name: cybersecurityNews.com
**React2Shell (CVE-2025-55182) is being actively and widely exploited** — the campaign has generated over 8.1 million attack sessions with daily volumes of 300k–400k, leveraging a distributed, cloud-heavy infrastructure (8,163 source IPs across 1,071 ASNs in 101 countries), over 70,000 unique payloads, numerous HTTP/TCP fingerprints, and a two-stage PowerShell exploitation flow employing AMSI bypass; organizations should urgently patch exposed React Server Components, implement dynamic blocking and endpoint monitoring for encoded PowerShell and AMSI tampering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
