React2Shell exploitation spreads as Microsoft counts hundreds of hacked machines
ID: 4fffd5ff-861c-5c2f-8fc9-4541ef76015f
STIX ID: report--4fffd5ff-861c-5c2f-8fc9-4541ef76015f
Feed Name: The Register (Security)
Threat Score
Microsoft and multiple security vendors report active exploitation of the critical React Server Components vulnerability (CVE-2025-55182, "React2Shell"): attackers have executed arbitrary commands, deployed memory-based downloaders, cryptominers, and in some incidents deployed ransomware across hundreds of compromised systems; telemetry indicates ongoing, large-scale abuse and many vulnerable instances remain unpatched, prompting urgent patching and auditing guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
