Risky Bulletin Newsletter
December 08, 2025
Risky Bulletin: APTs go after the React2Shell vulnerability within hours
Presented by
News Editor
At least two Chinese APT groups are exploiting a recently disclosed vulnerability in the React framework's server components.
Attacks began within hours after the vulnerability, tracked as CVE-2025-55182 and named React2Shell, was disclosed last Wednesday.
The AWS security team has linked the attacks to two groups tracked as Earth Lamia and Jackpot Panda.