A large-scale credential harvesting operation has been observed exploiting the React2Shell vulnerability as an initial infection vector to steal database credentials, SSH private keys, Amazon Web Services (AWS) secrets, shell command history, Stripe API keys, and GitHub tokens at scale. Cisco Talos
โกKey InsightsAI analyzingโฆ
I
info@thehackernews.com (The Hacker News)
๐ก
Original Source
The Hacker News
https://thehackernews.com/2026/04/hackers-exploit-cve-2025-55182-to.htmlTags:#security#the-hacker-news
Found this useful? Share it!
Read the Full Story
Continue reading on The Hacker News
Related Stories

๐Security
AI-Assisted Supply Chain Attack Targets GitHub
1 day ago

๐Security
Axios Attack Shows Social Complex Engineering Is Industrialized
1 day ago

๐Security
Fortinet Issues Emergency Patch for FortiClient Zero-Day
1 day ago

๐Security
Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations
1 day ago
