Google’s Threat Intelligence Group reports widespread, active exploitation of CVE-2025-55182 (“React2Shell”), an unauthenticated RCE in React Server Components, by both cybercrime and espionage clusters. Campaigns have dropped tunneling tools and backdoors (MINOCAT, SNOWLIGHT, HISONIC, COMPOOD) and cryptominers, while follow‑on React issues (CVE‑2025‑55183/55184/67779) have also emerged. GTIG urges immediate patching to fixed versions (19.0.1/19.1.2/19.2.1+) and 19.2.3 for DoS, deployment of WAF rules, dependency audits, and hunting for IOCs. Next.js users are similarly exposed due to vulnerable RSC packages.
Source: Google Threat Intelligence
Apple and Google push emergency updates after zero‑day attacks
Apple released urgent fixes for multiple platforms (iOS, macOS, watchOS, tvOS, visionOS, Safari) following reports of in‑the‑wild exploitation, while Google shipped a Chrome update tied to the same wave of targeted attacks. Organizations should fast‑track OS and browser updates, enable automatic patching, and review telemetry for suspicious browser or device activity linked to the exploited bugs.
Source: TechCrunch
CISA orders federal agencies to patch actively exploited GeoServer flaw
U.S. federal agencies have been directed to urgently remediate a GeoServer vulnerability now under active exploitation for intelligence collection. The bug has been added to CISA’s Known Exploited Vulnerabilities catalog, underscoring the risk to geospatial data systems widely used in government and critical infrastructure.
Source: SC Media
Gladinet CentreStack cryptographic bug exploited to breach at least nine organizations
Attackers are abusing a recently patched cryptographic algorithm flaw in Gladinet CentreStack (and older LFI CVE‑2025‑30406) to compromise organizations across sectors. The intrusions highlight the supply‑chain risk of file‑sharing/collaboration platforms and the need to rapidly apply security updates, harden internet exposure, and monitor for post‑exploitation activity.
Source: SecurityWeek
New NANOREMOTE Windows backdoor uses Google Drive for C2
Researchers discovered NANOREMOTE, a stealthy Windows backdoor that leverages the Google Drive API for command‑and‑control, with code overlaps to FINALDRAFT (REF7707). Drive‑based C2 blends with legitimate traffic, complicating detection; defenders should enforce egress controls, inspect OAuth/API usage, and hunt for anomalous Drive interactions from servers and endpoints.
Source: Security Affairs
Poisoned AI chats in Google ads push AMOS infostealer to Mac users
Malicious ads are elevating fake ChatGPT and Grok “conversations” in search results, funneling Mac users to payloads that install the Atomic macOS Stealer (AMOS). The campaign exploits user trust in AI branding; enterprises should tighten ad‑click policies, deploy macOS EDR, and educate users on spotting fake AI destinations.
Source: Malwarebytes
Germany summons Russian ambassador over APT28 cyberattack and election disinformation
Germany says it has “clear evidence” tying a 2024 cyberattack on its air traffic control authority to Russia’s APT28 (Fancy Bear), alongside coordinated disinformation aimed at elections. The escalation signals heightened geopolitical cyber risk to transportation and democratic processes, with likely implications for EU defensive postures and attribution.
Source: The Record by Recorded Future
You May Also Be Interested In...
Microsoft Bug Bounty Program Expanded to Third-Party CodeHalf of exposed React servers remain unpatched amid active exploitation
Notepad++ Patches Updater Flaw After Reports of Traffic Hijacking