Skip to main content

Share story

Security

Hackers exploit React2Shell vulnerability in large-scale automated credential theft campaign

Hackers exploit React2Shell vulnerability in large-scale automated credential theft campaign Image: Primary
Threat actors are actively exploiting a critical vulnerability in Next.js applications to conduct automated credential theft operations at scale. The campaign targets CVE-2025-55182, known as React2Shell, a flaw in the popular React-based web framework that enables remote code execution. Security researchers at BleepingComputer identified the attacks leveraging the vulnerability to compromise vulnerable applications and harvest user credentials systematically. The automated nature of the campaign suggests the use of specialized tooling to scan for and exploit internet-facing Next.js deployments. Next.js, maintained by Vercel, powers millions of websites including major enterprise applications. Organizations running affected versions are urged to apply patches immediately, as the vulnerability enables attackers to gain full control of application servers without authentication. The widespread use of Next.js in modern web development creates substantial attack surface, with the automated campaign indicating opportunistic but efficient exploitation by financially motivated threat actors.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Science
AI Science

AI agents develop physical model from quantum-material observations

Researchers report in an arXiv preprint that their AI Theorist system autonomously developed a physical model explaining previously unpublished experimental observations in α-RuCl₃, a candidate material for realizing a Kitaev quan...

Security Capital
Security Capital

Reco raises $55M extension for enterprise AI agent security

Reco raised a $55M Series B extension, bringing its total funding to $140M, TechCrunch reported. The company's technology helps enterprises secure and govern AI agents across software-as-a-service environments, where businesses ar...

Security
Security

ShinyHunters member reportedly detained in Jordan over FBI breach

ShinyHunters member Saif al-Din Khader, known as "Rey," was detained in Jordan and is cooperating to identify other hackers involved in the FBI breach, Reuters reported, citing sources. The hacking group claims to have stolen data...