Hackers Exploit Next.js React2Shell Vulnerability, Breach 766 Hosts in 24 Hours
ID: 4293b3da-2b15-5759-a288-a384299e57fd
STIX ID: report--4293b3da-2b15-5759-a288-a384299e57fd
Feed Name: GBHackers
Threat Score
Cisco Talos details an active mass-exploitation campaign (UAT-10608) abusing CVE-2025-55182 (React2Shell) in Next.js to achieve pre-auth RCE and deploy automated harvesting scripts that exfiltrate environment variables, SSH keys, cloud credentials, API keys and other secrets to a NEXUS Listener C2; telemetry shows at least 766 compromised hosts and 10,120 files exfiltrated, and defenders are urged to patch, rotate secrets, and harden server-side configurations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
