🦋 Live Bluesky Post

Matt Kane's avatar

Matt Kane

@mk.gg

Matt Kane

The @cloudflare.social threat intelligence team have published this great blog with a really detailed breakdown on the exploitation activity against React and Next.js. Some massive numbers of attempts, as well as confident attribution of the attacks as mostly coming from Chinese state actors.

React2Shell and related RSC vulnerabilities threat brief- early exploitation activity and threat actor techniques

blog.cloudflare.com

React2Shell and related RSC vulnerabilities threat brief- early exploitation activity and threat actor techniques

Early activity indicates that threat actors quickly integrated this vulnerability into their scanning and reconnaissance routines and targeted critical infrastructure including nuclear fuel, uranium a...

December 11, 2025 at 9:51 PM UTC