LexisNexis Hack Exposes 3.9M Records Through Unpatched React Vulnerability
ID: 0ccb2f91-65c5-586b-870a-24ec19922222
STIX ID: report--0ccb2f91-65c5-586b-870a-24ec19922222
Feed Name: TechRepublic Security
LexisNexis confirmed a breach after attackers exploited an unpatched React (React2Shell) vulnerability to access AWS containers and exfiltrate roughly 3.9 million records, 53 plaintext AWS Secrets, thousands of database tables, customer accounts, and VPC infrastructure maps; the actor FulcrumSec published over 2 GB of stolen files on dark web platforms. The company reports the impacted servers were limited and largely contained legacy data (pre-2020) and claims no exposure of SSNs, driver’s licenses, active passwords, or financial information; investigations and customer notifications are underway.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
