RondoDox Botnet Exploits Critical React2Shell Flaw to Hijack IoT Devices and Web Servers
A nine-month campaign used React2Shell (CVE-2025-55182) and other N-day flaws to enroll IoT devices and web apps into the RondoDox botnet, deploying miners and Mirai variants.
Cloudflare blames Friday outage on borked React2shell fix
Cloudflare intentionally took down its network to patch the critical React2Shell vulnerability, causing a major outage while denying any cyber attack caused it.
Cloudflare fixes second outage in a month | Computer Weekly
Cloudflare briefly lost Dashboard and API availability due to a WAF parsing change deployed to mitigate a critical React Server Components RCE (React2Shell) vulnerability, now resolved.