React2Shell flaw exploited to breach 30 orgs, 77k IP addresses vulnerable
ID: 00b0376f-9f09-588f-bf5a-875ebf7d42bb
STIX ID: report--00b0376f-9f09-588f-bf5a-875ebf7d42bb
Feed Name: Bleeping Computer
React2Shell (CVE-2025-55182) is a critical unauthenticated remote code execution flaw in React Server Components (affecting frameworks like Next.js) for which a public PoC was released; researchers observed automated scanning of ~77,664 vulnerable IPs and security vendors report more than 30 organizations compromised, with attackers using PowerShell-based loaders, disabling AMSI, and deploying Cobalt Strike, Snowlight and Vshell—activity linked to China-associated APTs. Organizations are urged to update React, rebuild and redeploy applications, and review logs for PowerShell/shell command activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
