UAT-10608 Uses a Next.js “React2Shell” Flaw to Map Your Entire Cloud
ID: 5a20a3ae-57cb-593e-aeb6-2c1aec3948dc
STIX ID: report--5a20a3ae-57cb-593e-aeb6-2c1aec3948dc
Feed Name: securityonline.info
Cisco Talos disclosed an active automated credential-harvesting campaign (UAT-10608) exploiting the React2Shell vulnerability (CVE-2025-55182) in Next.js applications to deploy a multi-stage harvester named "NEXUS Listener" that collects SSH keys, cloud tokens, environment and database credentials, and package registry tokens and exfiltrates them to a web-based C2 GUI; at least 766 hosts across multiple cloud providers have been compromised, enabling supply-chain attacks, targeted follow-on intrusions, and regulatory-impacting data exposures, and Talos recommends patching, strict secret management, and immediate rotation of potentially exposed credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
