BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

China-Linked Hackers Rapidly Exploit React2Shell RSC Flaw

China-linked hacking groups exploit critical React2Shell vulnerability, triggering AWS alerts and Cloudflare outage due to patch deployment

  • Two China-linked Hacking groups are exploiting a critical React Server Components vulnerability known as React2Shell (CVE-2025-55182).
  • The vulnerability allows unauthenticated remote code execution and affects React versions before 19.0.1, 19.1.2, and 19.2.1.
  • Amazon Web Services observed exploitation attempts by the Earth Lamia and Jackpot Panda groups targeting multiple sectors worldwide.
  • Cloudflare experienced a brief outage caused by a patch deployment for this vulnerability, not by a cyberattack.

Two hacking groups linked to China have rapidly exploited a newly revealed security flaw, CVE-2025-55182, affecting React Server Components (RSC). This maximum-severity vulnerability, also called React2Shell, allows unauthenticated remote code execution and has been addressed in React versions 19.0.1, 19.1.2, and 19.2.1.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

According to a report shared by Amazon Web Services (AWS), these groups, Earth Lamia and Jackpot Panda, have been detected attempting to exploit this flaw. AWS’s Chief Information Security Officer, CJ Moses, identified the threat actors’ infrastructure as historically tied to China state-sponsored groups, based on activity observed in AWS’s MadPot honeypot systems.

Earth Lamia previously exploited a critical SAP NetWeaver vulnerability (CVE-2025-31324) and has targeted sectors such as financial services, logistics, retail, IT, universities, and government organizations across Latin America, the Middle East, and Southeast Asia. Jackpot Panda’s targets primarily include entities involved in online gambling in East and Southeast Asia and have been active since at least 2020, known for supply chain compromises like the 2022 attack on the Comm100 chat application, tracked by ESET as Operation ChattyGoblin.

CrowdStrike reported Jackpot Panda’s use of trojanized installers targeting Chinese-speaking gambling communities, deploying implants with code similarities to Jackpot Panda’s unique CplRAT Malware. Additionally, a Chinese hacking contractor named I-Soon has been linked to some supply chain attacks associated with these activities.

AWS has also detected attempts to exploit other vulnerabilities, such as CVE-2025-1338 affecting NUUO Cameras, indicating a broader effort to scan for unpatched systems. Exploitation attempts observed include running system commands like “whoami,” writing files like “/tmp/pwned.txt,” and accessing sensitive files such as “/etc/passwd.” Moses stated this reflects a systematic campaign leveraging multiple vulnerabilities simultaneously to maximize successful intrusions.

- Advertisement -

In a related development, Cloudflare reported a brief network outage resulting in “500 Internal Server Error” responses. The company confirmed the issue stemmed from a Web Application Firewall update designed to mitigate the React2Shell vulnerability and clarified that the incident was not caused by an attack. More details are available in their official status report.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

$35M in Bitcoin seized after police crack lost wallet

Irish police, with Europol's help, have seized 500 Bitcoin (worth over $35 million) from...

Gold Crashes to 4-Month Low; Strategists Keep $5K–$6.3K Targets

Gold crashed to a four-month low of $4,098, posting its worst five-session performance since...

Baltimore sues xAI over Grok’s millions of non-consensual deepfakes

The Mayor and City Council of Baltimore have sued X Corp., xAI, and SpaceX,...

SpaceX Targets Historic $75B IPO Filing This Week

SpaceX may file for its record-breaking IPO as soon as this week, targeting a...

Ethereum Aims for Quantum Resistance by 2029

The Ethereum Foundation has launched a "Post-Quantum Ethereum" resource hub to address future quantum...

Must Read

Best Crypto Audiobooks of 2026: The Ultimate Listen & Learn Guide

You can't read Bitcoin charts while driving 70 mph on the highway. You can't study Ethereum whitepapers during your morning run. But you can...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading