Attacks pinned to critical React2Shell defect surge, surpass 50 confirmed victims
ID: e498dbd2-8eee-5b77-8da7-3cfb7df962de
STIX ID: report--e498dbd2-8eee-5b77-8da7-3cfb7df962de
Feed Name: CyberScoop
Threat Score
Security researchers and vendors report rapid, widespread exploitation of a critical React Server Components vulnerability (CVE-2025-55182, “React2Shell”) with more than 165,000 IPs and 644,000 domains identified as vulnerable; attackers including nation-state groups, botnets and cybercriminals are deploying a range of malware (cryptominers, backdoors, botnet malware) and multiple public PoCs and exploit attempts have been observed, prompting urgent patching guidance from authorities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
