Hackers Exploit Next.js React2Shell Flaw to Steal Credentials From 766 Hosts in 24 Hours
ID: 8399c362-fbdf-5d9c-811e-e56b866fc5d9
STIX ID: report--8399c362-fbdf-5d9c-811e-e56b866fc5d9
Feed Name: cybersecurityNews.com
Active mass exploitation of CVE-2025-55182 (React2Shell) in React Server Components affecting Next.js allowed unauthenticated RCE; automated scanning located vulnerable deployments and attackers breached at least 766 hosts within 24 hours, exfiltrating over 10,120 files including database credentials, SSH keys, cloud access tokens, GitHub and package registry tokens, and using a web-based C2 called NEXUS Listener to manage harvested data—organizations are advised to patch immediately, rotate secrets, audit cloud roles, enforce IMDSv2, avoid SSH key reuse and monitor outbound connections (notably to unknown IPs on port 8080).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
