
- React2Shell (CVE-2025-55182) critical flaw exploited by Chinese and North Korean groups
- North Korea deploys EtherRAT implant with Ethereum C2, Linux persistence, and Node.js runtime
- Researchers urge urgent updates to patched React versions 19.0.1, 19.1.2, and 19.2.1
The Chinese are not the only ones exploiting React2Shell, a maximum-severity vulnerability that was recently discovered in React Server Components (RSC).