AWS Warns of Data Exfiltration Risks from Outbound Traffic Blind Spots
ID: 3bac0d67-388b-530f-a9c4-65ba4669816e
STIX ID: report--3bac0d67-388b-530f-a9c4-65ba4669816e
Feed Name: ThreatCluster
Threat Score
AWS warns that CVE-2025-55182 (React2Shell), a pre-authentication RCE in React Server Components disclosed on December 3, 2025, has publicly available proof-of-concept code and is being actively exploited; unmonitored outbound traffic and absent egress controls in cloud environments can enable attackers to exfiltrate data, so organizations should implement layered egress detection and protection for cloud workloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
