Automated Credential Harvesting Campaign Targets React2Shell Vulnerability
Article Content
- •UAT-10608 has compromised over 766 hosts in just 24 hours.
- •The attack exploits the React2Shell vulnerability (CVE-2025-55182).
- •Sensitive data from major platforms, including AWS and GitHub, is at risk.
A large-scale automated credential harvesting campaign, tracked as UAT-10608, has compromised at least 766 hosts globally within 24 hours. The attackers exploit the React2Shell vulnerability (CVE-2025-55182), a pre-authentication remote code execution flaw affecting .js applications. This operation utilizes a framework called 'NEXUS Listener' to systematically harvest sensitive data, including usernames, passwords, SSH keys, and cloud tokens. Researchers from Cisco Talos discovered that an exposed web application allowed them to view the harvested data, which included credentials from major services like AWS, Microsoft Azure, and GitHub. The campaign's indiscriminate targeting pattern suggests automated scanning based on host profile data from services like Shodan. Organizations are urged to address this vulnerability promptly to prevent further credential theft. Talos is collaborating with affected service providers to notify victims and mitigate the impact.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (14)
Following this threat?
Track React2Shell, AWS and CVE-2025-55182 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Novo Nordisk Data Breach Exploits Hardcoded GitHub Tokens Novo Nordisk suffered a data breach linked to the cyber extortion group FulcrumSec, which exploited hardcoded credentials found in client-side JavaScript across two subdomains. The attackers accessed over 1 terabyte of sensitive data, including experimental drug data and customer records, after gaining entry in June…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…