• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Chinese Hacking Groups Exploit React2Shell Vulnerability Following Disclosure
Share
  • bitcoinBitcoin(BTC)$75,209.00
  • ethereumEthereum(ETH)$2,201.26
  • tetherTether(USDT)$1.00
  • binancecoinBNB(BNB)$740.30
  • rippleXRP(XRP)$1.56
  • usd-coinUSDC(USDC)$1.00
  • solanaSolana(SOL)$94.16
  • tronTRON(TRX)$0.284310
  • staked-etherLido Staked Ether(STETH)$2,260.93
  • dogecoinDogecoin(DOGE)$0.105675
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
Finance

Chinese Hacking Groups Exploit React2Shell Vulnerability Following Disclosure

News Desk
Last updated: December 5, 2025 6:15 pm
News Desk
Published: December 5, 2025
Share
React2Shell

A critical security flaw in React Server Components (RSC), identified as CVE-2025-55182 and rated with a CVSS score of 10.0, has quickly drawn the attention of cybercriminals, specifically two hacking groups linked to China. The vulnerability, which permits unauthenticated remote code execution, was disclosed recently and has already been exploited by threat actors aimed at targeting various sectors.

According to a recent report by Amazon Web Services (AWS), the groups—referred to as Earth Lamia and Jackpot Panda—have been observed exploiting this severe security flaw shortly after its public revelation. CJ Moses, Chief Information Security Officer at AWS, stated that their analysis of activity within the AWS MadPot honeypot infrastructure revealed attempts to exploit the flaw from IPs historically associated with known China-related threat actors.

Earth Lamia is notable for previous successful exploits, including a critical flaw in SAP NetWeaver earlier this year. This group has targeted a wide array of sectors, including financial services, logistics, retail, information technology, academia, and governmental organizations across Latin America, the Middle East, and Southeast Asia.

Jackpot Panda, another identified cyber threat actor, primarily focuses on entities tied to online gambling operations within East and Southeast Asia. Active since at least 2020, Jackpot Panda has been known to infiltrate trusted third-party relationships to deploy malicious implants and gain initial system access. A significant connection was made to this group in 2022, concerning a supply chain compromise related to the chat application Comm100. The group has also targeted Chinese-speaking victims, leading experts to suggest possible domestic surveillance efforts within China.

AWS’s report indicates that both Earth Lamia and Jackpot Panda are not merely exploiting the recent vulnerability in isolation. They also appear to be leveraging other known vulnerabilities, including CVE-2025-1338 in NUUO Camera, with a CVSS score of 7.3. Such activity suggests a systematic method of operation where threat actors vigilantly monitor new vulnerability disclosures and swiftly integrate public exploits into their scanning infrastructure. This approach significantly enhances their potential to locate vulnerable targets.

As these cybersecurity threats loom, Cloudflare experienced a brief but widespread outage attributed to the implementation of a patch addressing the React2Shell vulnerability. The web infrastructure provider confirmed that the outage, which resulted in numerous websites and online platforms displaying a “500 Internal Server Error,” was not the result of an attack but rather due to changes made on how their Web Application Firewall handles requests.

The urgency surrounding the React Server Components vulnerability has heightened awareness across the tech industry, emphasizing the need for immediate upgrades to the latest React versions—19.0.1, 19.1.2, and 19.2.1—to mitigate potential risks posed by these cyber threat actors.

Boeing Workers Reject New Contract Proposal, Continue Strike at Midwest Plants
Starbucks Workers Strike on Red Cup Day for Better Wages and Benefits
Visa and Mastercard Propose Settlement to Alter Merchant Card Acceptance Rules
Trump Administration Set to Announce Deals to Cut Prices of Popular Weight Loss Drugs
Trump Reveals Possible Backers for TikTok Deal Including Rupert Murdoch and Michael Dell
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article urlhttps3A2F2Fg.foolcdn.com2Feditorial2Fimages2F8455192Fshibdog.jpegw1200opresize Vanguard’s Policy Reversal Boosts Shiba Inu and Crypto Market
Next Article 87623039007 erictrumpbg iawubojizba 2 tgozfyhq 4 zysiy Eric Trump’s American Bitcoin Corp. Shares Plunge 70% Three Months After Nasdaq Debut
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
1767101674 ce6e5878a3bba05bcb92f58c5d32dad187180ea3 1920x1080
Citi Warns Crypto Markets At Critical Juncture Amid Continued Declines and Regulatory Concerns
cd606e60 014b 11f1 9b7d cf7fc07d3a05
AI Stock Rout Deepens as Software Companies Face Disruption Fears
69827923a645d1188188a04b
Bitcoin Faces Significant Sell-Off Amid Hawkish Federal Reserve Nominations and Regulatory Delays
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Finance
  • News
  • Company
  • Stocks
  • Bitcoin
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?