Attackers rapidly weaponized React2Shell (CVE-2025-55182), a critical flaw in React Server Components and React/Next.js applications that enables unauthenticated remote code execution. Security reporting described the bug as one of the most consequential vulnerabilities of the year, with exploitation spreading across criminal and state-linked operations and defenders urged to prioritize emergency patching and monitoring. The flaw was also tied to broader shifts in the threat landscape, including more resilient malware campaigns, cloud-focused intrusions, and increasingly AI-enabled attack activity.
Large-scale exploitation followed disclosure, with more than 8.1 million attack sessions observed from over 8,000 unique source IPs spanning 101 countries, including substantial traffic routed through major cloud providers such as AWS. Researchers also linked the vulnerability to follow-on malware activity, including the EtherRAT campaign, which used Ethereum smart contracts for command-and-control, while reporting highlighted advanced evasion methods such as AMSI bypass and rapid IP rotation that reduced the effectiveness of static defenses. The volume and sophistication of the attacks underscored the need for behavioral detection, dynamic threat intelligence, and immediate remediation of exposed internet-facing systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Cyber Security News reported that attackers had launched more than 8.1 million attack sessions against React2Shell since its disclosure. The activity used over 8,000 unique source IPs across 101 countries, with substantial traffic originating from major cloud providers and employing rapid IP rotation and AMSI-bypass techniques.
Sysdig reported a DDoS attack that disrupted French postal and banking services. The incident was cited among notable cybersecurity events observed in December 2025.
Sysdig reported that the European Space Agency suffered a breach involving significant data theft. According to the report, network segmentation limited the overall impact of the incident.
Sysdig's Threat Research Team identified EtherRAT, a sophisticated multi-stage malware campaign that used Ethereum smart contracts for command-and-control and exploited React2Shell. The campaign was highlighted as part of the December 2025 threat landscape.
PolySwarm described React2Shell (CVE-2025-55182) as the most impactful vulnerability of 2025, saying the flaw in React/Next.js applications enabled unauthenticated remote code execution and was rapidly weaponized by both state-sponsored and criminal actors. Separate reporting also described active exploitation of the flaw in December 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityboulevard.com
Open sourcesysdig.com
Open sourceblog.polyswarm.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.