Threat actors are rapidly exploiting a critical pre-auth RCE in React Server Components, with mass scanning and active compromises observed across internet-exposed Next.js/React apps. The flaw (dubbed React2Shell) enables deserialization-driven code execution; security teams are urged to patch immediately, audit logs for RSC payload anomalies, and review downstream systems for post-exploitation activity.
Source: SecurityWeek
New BYOVD loader lets DeadLock ransomware disable EDR via vulnerable Baidu driver
Cisco Talos uncovered a DeadLock ransomware campaign using a previously unknown bring-your-own-vulnerable-driver (BYOVD) loader to exploit a Baidu Antivirus driver bug. The technique allows attackers to kill endpoint defenses and escalate privileges, underscoring the need to enforce kernel driver blocklists and restrict unsigned/legacy drivers in enterprise fleets.
Source: Cisco Talos
US Treasury: Ransomware payments surpassed $4.5B since 2013, hit record $1.1B in 2023
FinCEN data shows a sustained rise in ransomware payments, with 2023 marking the highest annual total reported. The findings reinforce the urgency of hardening backup/restore processes, reducing exposed RDP/VPN attack surfaces, and accelerating response playbooks to limit dwell time and extortion leverage.
Source: SecurityWeek
Critical Apache Tika bug enables XXE via PDFs, threatens content indexing pipelines
A maximum-severity vulnerability in Apache Tika’s core, PDF, and parser modules allows XML External Entity (XXE) injection through crafted XFA-in-PDF files. Because Tika underpins many enterprise search, e-discovery, and ingestion workflows, defenders should patch urgently and review for unexpected outbound requests or parser crashes indicative of XXE testing.
Source: SecurityWeek
Google adds layered defenses to Chrome’s agentic AI against prompt injection
To counter indirect prompt injection attacks, Chrome introduces a “User Alignment Critic” to vet agent actions, tighter origin isolation to constrain agent reach, and added user confirmations for sensitive steps. The model- and browser-level controls aim to reduce goal hijacking and data exfiltration risks as agentic browsing rolls out.
Source: SecurityWeek
Clop exploited Oracle E‑Business Suite zero‑day to steal data from Barts Health NHS
Barts Health NHS confirmed sensitive data theft after attackers used an Oracle EBS zero-day (CVE-2025-61882). The incident highlights ERP supply-chain exposure and the importance of aggressive patch management, network segmentation, and least-privilege access around high-value business systems.
Source: Security Affairs
Hypervisor ransomware attacks jump 700% as adversaries target ESXi and Hyper‑V
Researchers report a dramatic rise in ransomware directly hitting virtualization layers, magnifying blast radius and recovery complexity. Organizations should harden management interfaces, enforce MFA and allowlists, restrict shell access, patch hypervisors promptly, and test hypervisor-aware backup and restore procedures.
Source: The Register
You May Also Be Interested In...
CISA adds Meta React Server Components flaw to Known Exploited Vulnerabilities
NCSC UK: Prompt injection is not SQL injection (it may be worse)
Dozens of AI coding tool vulnerabilities discovered (“IDEsaster”)