Half of exposed React servers remain unpatched amid attacks
Half of internet-facing React server systems remain unpatched against CVE-2025-55182, enabling widespread unauthenticated remote code execution exploitation across diverse attack clusters.
Chinese state-backed groups actively weaponized React2Shell (CVE-2025-55182) within hours, enabling unauthenticated remote code execution against React 19.x and Next.js App Router.
ThreatsDay Bulletin: Spyware Alerts, Mirai Strikes, Docker Leaks, ValleyRAT Rootkit - and 20 More Stories
New widespread exploitations and undetected malware rapidly increase risk across consumer and enterprise devices while defenders race to patch and investigate.
North Korea-linked Actors Exploit React2Shell to Deploy New EtherRAT Malware
North Korea-linked actors exploited the React2Shell RSC vulnerability to deploy EtherRAT, a Node.js-based RAT that uses Ethereum smart contracts for command-and-control.
Weekly Recap: USB Malware, React2Shell, WhatsApp Worms, AI IDE Bugs & More
Critical React Server Components vulnerability CVE-2025-55182 (React2Shell) enables unauthenticated remote code execution and is being exploited within hours of disclosure.
React2Shell (CVE-2025-55182) is a critical remote code execution vulnerability in React Server Components with CVSS 10.0 and rapid, widespread exploitation risk.
Cloudflare blames Friday outage on borked React2shell fix
Cloudflare intentionally took down its network to patch the critical React2Shell vulnerability, causing a major outage while denying any cyber attack caused it.