logo

Beijing-linked hackers are hammering max-severity React bug, AWS warns

ID: 298bb154-c1c5-5622-89a7-542de0c02a00

STIX ID: report--298bb154-c1c5-5622-89a7-542de0c02a00

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-12-05

Date Updated: 2026-04-26

Author: Carly Page

...
...

Amazon observed China-linked state-nexus groups (including Earth Lamia and Jackpot Panda) rapidly exploiting CVE-2025-55182 (“React2Shell”), a CVSS-10 remote-code-execution flaw in React Server Components and dependent frameworks, with scanning and exploit traffic captured in AWS MadPot honeypots; vendors and researchers warn of widespread exposure (Wiz estimated ~39% of cloud environments vulnerable) and urge immediate patching while noting rapid operationalization of public PoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.