CVE
CVE-2025-55182
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
Exploitation IoCs 2
Domain ethereum[.]ens
Domain solana[.]sns
MITRE ATT&CK TTPs 22
T1021.004 T1059 T1059.001 T1070.001 T1071.001 T1078 T1098 T1110 T1133 T1190 T1203 T1210 T1211 T1218 T1485 T1566 T1569 T1570 T1589 T1595 T1599 T1650
SSH
Lateral Movement
Command and Scripting Interpreter
Execution
PowerShell
Execution
Clear Windows Event Logs
Defense Evasion
Web Protocols
Command And Control
Valid Accounts
Defense Evasion
Account Manipulation
Persistence
Brute Force
Credential Access
External Remote Services
Persistence
Exploit Public-Facing Application
Initial Access
Exploitation for Client Execution
Execution
Exploitation of Remote Services
Lateral Movement
Exploitation for Defense Evasion
Defense Evasion
System Binary Proxy Execution
Defense Evasion
Data Destruction
Impact
Phishing
Initial Access
System Services
Execution
Lateral Tool Transfer
Lateral Movement
Gather Victim Identity Information
Reconnaissance
Active Scanning
Reconnaissance
Network Boundary Bridging
Defense Evasion
Acquire Access
Resource Development
Source Articles
New Dysphoria DDoS botnet spreads to 200k devices worldwide
The Dysphoria DDoS botnet has infected approximately 200,000 devices worldwide by exploiting weak credentials and known vulnerabilities in IoT devices. It evolved from 'jackskid' and 'fbot' malware, incorporating a blockchain-based command-and-control mechanism using Ethereum ENS and Solana SNS domains for resilience. The botnet conducts DDoS attacks and can transform infected devices into network proxies, leveraging UPnP to expose internal services. Its operators claim a maximum attack capacity of 4 Tbps, promoting the service on a clearnet website as a stress-testing tool.
bleeping-computer Jul 27, 2026
Next.js moves to scheduled security releases
Next.js is transitioning to a scheduled security release model to address vulnerabilities in a predictable and coordinated manner, replacing ad-hoc patching. This change follows high-severity incidents like React2Shell (CVE-2025-55182), a critical remote code execution flaw in React Server Components that was widely exploited. The new program enables advance notice of patches, allowing organizations time to plan upgrades and implement mitigations. Vercel cites increasing vulnerability discovery rates due to AI-assisted tools as a driver for more frequent and structured releases.
socket-dev
No Manners Here: The Ruthless Rise of The Gentlemen Ransomware
The Gentlemen, also known as Storm-2697, is a Ransomware-as-a-Service (RaaS) operation active since July 2025, believed to have evolved from the Qilin RaaS affiliate ArmCorp. They offer affiliates an unusually high 90% ransom payout, contributing to rapid growth, with over 580 victims claimed across 77 countries by mid-2026. The group uses diverse initial access methods, custom tools like the 'GentleKiller' EDR killer, and exploits vulnerabilities in edge devices and protocols to target enterprises, particularly in manufacturing.
unit42 Jul 10, 2026