Multiple critical vulnerabilities affecting React Server Components and .js have been disclosed, including denial of service, server-side request forgery, and middleware bypass issues. These flaws impact versions 13.x…
On December 3, 2025, Meta disclosed CVE-2025-55182, a critical remote code execution vulnerability dubbed React2Shell, affecting React Server Components. The flaw arises from improper type validation in the Flight…
In March 2026, the EvilTokens phishing kit emerged as a significant threat, allowing cybercriminals to bypass multi-factor authentication (MFA) and compromise Microsoft 365 accounts. This Phishing-as-a-Service (PhaaS)…
A cybersecurity researcher named Eaton disclosed vulnerabilities in Johnson & Johnson's web applications affecting their Campus Recruiting platform and Audit Tracking Management System (ATMS). The flaws allowed…
A campaign involving 148 malicious npm packages, branded as student proxy tools, has been uncovered. These packages were designed to lure students into bypassing school web filters but instead turned their browsers into…
A critical vulnerability tracked as CVE-2026-0969 was disclosed in the -mdx-remote library, allowing attackers to execute arbitrary code on servers that render untrusted MDX content. The vulnerability affects versions…
Lovable, a vibe-coding platform, is under scrutiny after a researcher revealed a significant data exposure issue affecting all projects created before November 2025. The researcher, known as @weezerOSINT, demonstrated…
In 2026, the Model Context Protocol (MCP) has been identified as a significant security risk due to its unverified package management and decentralized registry ecosystem. This vulnerability allows attackers to exploit…
A critical vulnerability with a CVSS score of 10.0 has been identified in React Server Components, specifically affecting the Flight protocol. This flaw allows unauthenticated attackers to execute remote code, impacting…
A maximum-severity vulnerability in the React JavaScript library, tracked as CVE-2025-55182, allows unauthenticated remote code execution on affected instances. Security researchers report that 39 percent of cloud…