New PCPcat Exploiting React2Shell Vulnerability to compromise 59,000+ Servers
A new malware campaign called PCPcat has successfully compromised more than 59,000 servers in under 48 hours through targeted exploitation of critical vulnerabilities in .js and React frameworks. The malware targets .js deployments by exploiting two critical vulnerabilities, CVE-2025-29927 and CVE-2025-66478, which allow remote code execution without authentication. The attack uses prototype pollution and command […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
