Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts, Steal Credentials

A large-scale credential harvesting operation has been observed exploiting the React2Shell vulnerability as an initial infection vector to steal database credentials, SSH private keys, Amazon Web Services (AWS) secrets, shell command history, Stripe API keys, and GitHub tokens at scale.
Cisco Talos has attributed the operation to a threat cluster it tracks as

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto Miners

Next Post

Drift Loses $285 Million in Durable Nonce Social Engineering Attack Linked to DPRK

Related Posts
Total
0
Share