Related Threat Clusters
-
Critical React2Shell RCE Vulnerability Exploited in the Wild
The React2Shell remote code execution (RCE) vulnerability has been actively exploited to execute malicious code. This flaw affects various systems using the React framework, posing significant risks to organizations.…
2 articles · Updated December 8, 2025 -
RondoDox Botnet Targets React2Shell Flaw to Spread Malware
The RondoDox botnet is exploiting the React2Shell vulnerability (CVE-2025-55182) to infect vulnerable .js servers with malware and cryptominers. This ongoing campaign has been active for nine months, primarily targeting…
12 articles · Updated January 1, 2026 -
Critical NGINX UI Vulnerability CVE-2026-33032 Under Active Exploitation
A critical vulnerability in the nginx-ui web server management tool, tracked as CVE-2026-33032, has been actively exploited since March 2026. This flaw allows attackers to bypass authentication on the /mcp_message…
22 articles · Updated April 15, 2026 -
AWS Warns of Data Exfiltration Risks from Outbound Traffic Blind Spots
AWS has highlighted the risks associated with unmonitored outbound traffic in cloud environments, particularly in light of the CVE-2025-55182 vulnerability affecting React Server Components. This vulnerability allows…
4 articles · Updated June 23, 2026 -
ChocoPoC Malware Targets Cybersecurity Researchers via Trojanized GitHub Exploits
A coordinated supply chain attack has been identified, targeting vulnerability researchers and penetration testers through malicious proof-of-concept (PoC) repositories on GitHub. The malware, named ChocoPoC, is a…
10 articles · Updated July 1, 2026 -
Rapid Exploitation of Vulnerabilities in 2025: Insights from Cisco Talos
In 2025, Cisco's Talos reported a significant increase in the speed at which cybercriminals exploit vulnerabilities, particularly highlighting the React2Shell vulnerability disclosed in December 2025, which became the…
8 articles · Updated March 23, 2026 -
Automated Credential Harvesting Campaign Targets React2Shell Vulnerability
A large-scale automated credential harvesting campaign, tracked as UAT-10608, has compromised at least 766 hosts globally within 24 hours. The attackers exploit the React2Shell vulnerability (CVE-2025-55182), a…
14 articles · Updated April 3, 2026 -
GreyNoise Report Reveals Early Warning Signals for Edge Device Vulnerabilities
GreyNoise Intelligence has released a report indicating that spikes in malicious activity often precede the disclosure of new vulnerabilities in edge devices. The study tracked 147.8 million sessions over 103 days,…
13 articles · Updated April 20, 2026 -
Evolution of Chinese-Nexus Cyber Operations: Strategic Long-Term Threats
Recent research from Darktrace reveals the evolution of Chinese-nexus cyber operations over the past two decades, highlighting a shift from high-volume attacks to more strategic, identity-centric intrusions. This change…
381 articles · Updated April 2, 2026 -
Critical React2Shell RCE Vulnerability Disclosed by Meta
On December 3, 2025, Meta disclosed CVE-2025-55182, a critical remote code execution vulnerability dubbed React2Shell, affecting React Server Components. The flaw arises from improper type validation in the Flight…
2 articles · Updated May 9, 2026
Recent Intelligence Reports
- LexisNexis pulls three services offline after suspicious server activity — Theregister · August 10, 2026
- LexisNexis shuts down services after suspicious activity on servers — Bleepingcomputer · August 10, 2026
- LexisNexis shuts down services after suspicious activity on servers — Bleepingcomputer · August 10, 2026
- Criminals Use AI to Build Botnets, Steal Crypto, and Hijack Live Cameras — Technadu · August 5, 2026
- Extending AI Security Visibility with Darktrace and Microsoft Agent 365 — Darktrace · August 4, 2026
- Cloud and SaaS Environments Now Top Targets for Attackers — Infosecurity-Magazine · August 4, 2026
- Why Trust is the New Attack Surface: Darktrace's Mid — Darktrace · August 3, 2026
- New Dysphoria DDoS botnet spreads to 200k devices worldwide — Bleepingcomputer · July 27, 2026