Automated Credential Harvesting Campaign Exploits React2Shell Flaw
ID: 84d84fc8-295f-5374-9da6-5afc9c7c7576
STIX ID: report--84d84fc8-295f-5374-9da6-5afc9c7c7576
Feed Name: Dark Reading
Cisco Talos identified a global automated campaign (attributed to UAT-10608) exploiting the React2Shell pre-auth RCE (CVE-2025-55182) in Next.js Server Components to deploy the NEXUS Listener credential-harvesting framework, resulting in at least 766 compromised hosts and large-scale exfiltration of SSH keys, cloud tokens, and environment secrets; mitigations include patching, credential rotation, least-privilege enforcement, metadata access restriction, secrets scanning, and monitoring for specific forensic artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
