• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Chinese Hacking Groups Exploit React2Shell Vulnerability Following Disclosure
Share
  • bitcoinBitcoin(BTC)$71,078.00
  • ethereumEthereum(ETH)$2,163.07
  • tetherTether(USDT)$1.00
  • rippleXRP(XRP)$1.44
  • binancecoinBNB(BNB)$638.70
  • usd-coinUSDC(USDC)$1.00
  • solanaSolana(SOL)$91.52
  • tronTRON(TRX)$0.304080
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03
  • dogecoinDogecoin(DOGE)$0.095091
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
Finance

Chinese Hacking Groups Exploit React2Shell Vulnerability Following Disclosure

News Desk
Last updated: December 5, 2025 6:15 pm
News Desk
Published: December 5, 2025
Share
React2Shell

A critical security flaw in React Server Components (RSC), identified as CVE-2025-55182 and rated with a CVSS score of 10.0, has quickly drawn the attention of cybercriminals, specifically two hacking groups linked to China. The vulnerability, which permits unauthenticated remote code execution, was disclosed recently and has already been exploited by threat actors aimed at targeting various sectors.

According to a recent report by Amazon Web Services (AWS), the groups—referred to as Earth Lamia and Jackpot Panda—have been observed exploiting this severe security flaw shortly after its public revelation. CJ Moses, Chief Information Security Officer at AWS, stated that their analysis of activity within the AWS MadPot honeypot infrastructure revealed attempts to exploit the flaw from IPs historically associated with known China-related threat actors.

Earth Lamia is notable for previous successful exploits, including a critical flaw in SAP NetWeaver earlier this year. This group has targeted a wide array of sectors, including financial services, logistics, retail, information technology, academia, and governmental organizations across Latin America, the Middle East, and Southeast Asia.

Jackpot Panda, another identified cyber threat actor, primarily focuses on entities tied to online gambling operations within East and Southeast Asia. Active since at least 2020, Jackpot Panda has been known to infiltrate trusted third-party relationships to deploy malicious implants and gain initial system access. A significant connection was made to this group in 2022, concerning a supply chain compromise related to the chat application Comm100. The group has also targeted Chinese-speaking victims, leading experts to suggest possible domestic surveillance efforts within China.

AWS’s report indicates that both Earth Lamia and Jackpot Panda are not merely exploiting the recent vulnerability in isolation. They also appear to be leveraging other known vulnerabilities, including CVE-2025-1338 in NUUO Camera, with a CVSS score of 7.3. Such activity suggests a systematic method of operation where threat actors vigilantly monitor new vulnerability disclosures and swiftly integrate public exploits into their scanning infrastructure. This approach significantly enhances their potential to locate vulnerable targets.

As these cybersecurity threats loom, Cloudflare experienced a brief but widespread outage attributed to the implementation of a patch addressing the React2Shell vulnerability. The web infrastructure provider confirmed that the outage, which resulted in numerous websites and online platforms displaying a “500 Internal Server Error,” was not the result of an attack but rather due to changes made on how their Web Application Firewall handles requests.

The urgency surrounding the React Server Components vulnerability has heightened awareness across the tech industry, emphasizing the need for immediate upgrades to the latest React versions—19.0.1, 19.1.2, and 19.2.1—to mitigate potential risks posed by these cyber threat actors.

Regional Banks Poised for Recovery as Earnings Season Approaches
Japan’s Nikkei 225 Hits Historic 58,000 Mark Amid Post-Election Rally
Frustration Mounts as YouTube TV Subscribers Miss College Football Action Amid Disney Dispute
Investors Retreat as $1.80 Billion Exits Spot Crypto ETFs Amid Market Volatility
Trump Proposes Universal Retirement Accounts with Government Match for Millions of Uninsured Workers
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article urlhttps3A2F2Fg.foolcdn.com2Feditorial2Fimages2F8455192Fshibdog.jpegw1200opresize Vanguard’s Policy Reversal Boosts Shiba Inu and Crypto Market
Next Article 87623039007 erictrumpbg iawubojizba 2 tgozfyhq 4 zysiy Eric Trump’s American Bitcoin Corp. Shares Plunge 70% Three Months After Nasdaq Debut
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
34d298f0 2642 11f1 bfbc e5efeb131aaf
Oil Prices Fluctuate Amid Trump’s Ultimatum to Iran
ada1d41c07bb000efdd4f32c6fa0d944
Progress in U.S.-Iran Talks Eases Geopolitical Tensions, Boosts Markets
1774289277 og
Polymarket Traders Set Real-Time Odds on Bitcoin Price Movements
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Company
  • Finance
  • News
  • Stocks
  • Bitcoin
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?