CVE

CVE-2025-55182

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

Exploitation IoCs 2

Domain ethereum[.]ens
Domain solana[.]sns

MITRE ATT&CK TTPs 22

Source Articles

New Dysphoria DDoS botnet spreads to 200k devices worldwide
The Dysphoria DDoS botnet has infected approximately 200,000 devices worldwide by exploiting weak credentials and known vulnerabilities in IoT devices. It evolved from 'jackskid' and 'fbot' malware, incorporating a blockchain-based command-and-control mechanism using Ethereum ENS and Solana SNS domains for resilience. The botnet conducts DDoS attacks and can transform infected devices into network proxies, leveraging UPnP to expose internal services. Its operators claim a maximum attack capacity of 4 Tbps, promoting the service on a clearnet website as a stress-testing tool.
bleeping-computer Jul 27, 2026
Next.js moves to scheduled security releases
Next.js is transitioning to a scheduled security release model to address vulnerabilities in a predictable and coordinated manner, replacing ad-hoc patching. This change follows high-severity incidents like React2Shell (CVE-2025-55182), a critical remote code execution flaw in React Server Components that was widely exploited. The new program enables advance notice of patches, allowing organizations time to plan upgrades and implement mitigations. Vercel cites increasing vulnerability discovery rates due to AI-assisted tools as a driver for more frequent and structured releases.
socket-dev
No Manners Here: The Ruthless Rise of The Gentlemen Ransomware
The Gentlemen, also known as Storm-2697, is a Ransomware-as-a-Service (RaaS) operation active since July 2025, believed to have evolved from the Qilin RaaS affiliate ArmCorp. They offer affiliates an unusually high 90% ransom payout, contributing to rapid growth, with over 580 victims claimed across 77 countries by mid-2026. The group uses diverse initial access methods, custom tools like the 'GentleKiller' EDR killer, and exploits vulnerabilities in edge devices and protocols to target enterprises, particularly in manufacturing.
unit42 Jul 10, 2026