Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability

    Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability

    Dec 05, 2025Ravie LakshmananVulnerability / Software Security Two hacking groups with ties to China have been observed weaponizing the newly disclosed security flaw in React Server Components (RSC) within hours of it becoming public knowledge. The vulnerability in question is CVE-2025-55182 (CVSS score: 10.0), aka React2Shell, which allows unauthenticated remote code execution. It has been…

    Read More
    CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems

      CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems

      The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday released details of a backdoor named BRICKSTORM that has been put to use by state-sponsored threat actors from the People’s Republic of China (PRC) to maintain long-term persistence on compromised systems. “BRICKSTORM is a sophisticated backdoor for VMware vSphere and Windows environments,” the agency said….

      Read More
      Hackers Exploit Azure Apps to Create Malicious Apps Impersonating Microsoft

      Hackers Exploit Azure Apps to Create Malicious Apps Impersonating Microsoft

      A recent investigation by Varonis Threat Labs uncovered a critical loophole that allowed attackers to create malicious Azure applications using reserved Microsoft names. By bypassing safeguards, hackers could register deceptive app names like “Azure Portal,” tricking users into granting dangerous permissions. This flaw enabled cybercriminals to gain initial access, maintain persistence, and escalate privileges within…

      Read More