Related Threat Clusters
-
RondoDox Botnet Targets React2Shell Flaw to Spread Malware
The RondoDox botnet is exploiting the React2Shell vulnerability (CVE-2025-55182) to infect vulnerable .js servers with malware and cryptominers. This ongoing campaign has been active for nine months, primarily targeting…
12 articles · Updated January 1, 2026 -
Critical NGINX UI Vulnerability CVE-2026-33032 Under Active Exploitation
A critical vulnerability in the nginx-ui web server management tool, tracked as CVE-2026-33032, has been actively exploited since March 2026. This flaw allows attackers to bypass authentication on the /mcp_message…
22 articles · Updated April 15, 2026 -
AWS Warns of Data Exfiltration Risks from Outbound Traffic Blind Spots
AWS has highlighted the risks associated with unmonitored outbound traffic in cloud environments, particularly in light of the CVE-2025-55182 vulnerability affecting React Server Components. This vulnerability allows…
4 articles · Updated June 23, 2026 -
ChocoPoC Malware Targets Cybersecurity Researchers via Trojanized GitHub Exploits
A coordinated supply chain attack has been identified, targeting vulnerability researchers and penetration testers through malicious proof-of-concept (PoC) repositories on GitHub. The malware, named ChocoPoC, is a…
10 articles · Updated July 1, 2026 -
Automated Credential Harvesting Campaign Targets React2Shell Vulnerability
A large-scale automated credential harvesting campaign, tracked as UAT-10608, has compromised at least 766 hosts globally within 24 hours. The attackers exploit the React2Shell vulnerability (CVE-2025-55182), a…
14 articles · Updated April 3, 2026 -
GreyNoise Report Reveals Early Warning Signals for Edge Device Vulnerabilities
GreyNoise Intelligence has released a report indicating that spikes in malicious activity often precede the disclosure of new vulnerabilities in edge devices. The study tracked 147.8 million sessions over 103 days,…
13 articles · Updated April 20, 2026 -
Evolution of Chinese-Nexus Cyber Operations: Strategic Long-Term Threats
Recent research from Darktrace reveals the evolution of Chinese-nexus cyber operations over the past two decades, highlighting a shift from high-volume attacks to more strategic, identity-centric intrusions. This change…
381 articles · Updated April 2, 2026 -
Critical React2Shell RCE Vulnerability Disclosed by Meta
On December 3, 2025, Meta disclosed CVE-2025-55182, a critical remote code execution vulnerability dubbed React2Shell, affecting React Server Components. The flaw arises from improper type validation in the Flight…
2 articles · Updated May 9, 2026 -
North Korean Hackers Exploit React2Shell Vulnerability in Crypto Sector
A group of hackers suspected to be linked to North Korea has targeted cryptocurrency firms, exploiting the React2Shell vulnerability (CVE-2025-55182). The attackers compromised AWS access credentials to infiltrate cloud…
8 articles · Updated March 9, 2026 -
Dysphoria Botnet Infects 200,000 Devices Using Blockchain for C2 Operations
The Dysphoria botnet has compromised approximately 200,000 devices globally, utilizing a sophisticated command-and-control (C2) infrastructure hidden behind Ethereum and Solana blockchain domains. Originating from the…
5 articles · Updated July 28, 2026
Recent Intelligence Reports
- TeamPCP (UNC6780): From Telegram Data Broker to Supply Chain Cascade — Kelacyber · August 27, 2026
- Rebuilt in Six Days: Dysphoria IoT Botnet Hides on Blockchain to Defy Seizure — Techtimes · July 29, 2026
- New Dysphoria DDoS botnet spreads to 200k devices worldwide — Bleepingcomputer · July 27, 2026
- Weekly Threat Bulletin February 11th 2026 — www.f5.com · July 2, 2026
- Dont Eat The Chocopocs How Vulnerability Researchers Were Repeatedly Targeted By Trojanised Exploits — www.sekoia.com · July 2, 2026
- CVE-2025-55182 — nvd.nist.gov · July 2, 2026
- Vect and TeamPCP partner for ransomware campaigns — Sophos · July 2, 2026
- Vect and TeamPCP partner for ransomware campaigns — News.Sophos · July 2, 2026