Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Summary Note: This joint Cybersecurity Advisory is being published as an addition to the Cybersecurity and Infrastructure Security Agency (CISA) May 6, 2025, joint fact sheet Primary Mitigations to Reduce Cyber Threats to Operational Technology and European Cybercrime Centre’s (EC3) Operation...
CISA warns of pro-Russia hacktivists conducting opportunistic attacks against US and global critical infrastructure organizations. The attackers primarily use DDoS and website defacement techniques to cause disruption.
A critical vulnerability, CVE-2025-55182 (dubbed React2Shell), was discovered in React on December 3, 2025, allowing unauthenticated remote code execution (RCE). Cybereason researchers warn the flaw is trivial to exploit, as servers incorrectly trust user-supplied identifiers without proper verification.
This article announces CVE-2025-55182, a critical unauthenticated remote code execution vulnerability in React. Cybereason experts have found it trivial to exploit and have observed a public PoC attributed to Chinese threat actors.
<img src="https://www.cybereason.com/hubfs/BLOG_Images_Template_v2%20%2836%29.
This article outlines CVE-2025-55182, a critical pre-authentication remote code execution vulnerability in React Server Components. It affects React, Next.js, and related frameworks.