After React2Shell: Following the Attacker From Access to Impact

React2Shell (CVE-2025-55182) is a critical unauthenticated remote code execution vulnerability in React Server Components that allows attackers to deliver malicious Flight payloads and achieve code execution on servers running React 19.x with Server Components. It was rapidly weaponized with public PoCs, Metasploit modules, large-scale scanning, confirmed compromises, and nation-state exploitation—forcing KEV listing and causing operational impacts reported by providers like Cloudflare. #React2Shell #CVE-2025-55182

Read More
React2Shell flaw exploited to breach 30 orgs, 77k IP addresses vulnerable

Over 77,000 IP addresses are vulnerable to the critical React2Shell remote code execution flaw (CVE-2025-55182), with attackers already compromising over 30 organizations. Widespread exploitation involves Chinese threat actors using PowerShell and malware like Snowlight and Vshell to access and control affected systems. #React2Shell #CVE-2025-55182 #ChineseThreatActors

Read More
Sharpening the knife: GOLD BLADE’s strategic evolution

Sophos linked nearly 40 STAC6565 intrusions (Feb 2024–Aug 2025) to the GOLD BLADE group, which has evolved from espionage into a hybrid operation that mixes targeted data theft with selective ransomware deployment using a custom locker called QWCrypt. The group refines RedLoader delivery chains, abuses recruitment platforms to deliver weaponized resumes, leverages BYOVD drivers and modified Terminator tools for EDR evasion, and uses RPivot/Chisel for tunneled C2. #GOLD_BLADE #QWCrypt

Read More
CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems

CISA has revealed details of BRICKSTORM, a sophisticated backdoor used by Chinese state-sponsored threat actors to maintain long-term access on VMware vSphere and Windows systems. The malware is employed in targeting government and IT sectors, supporting covert command-and-control operations through various protocols and concealment techniques. #BRICKSTORM #WarpPanda…

Read More
Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery

A new report reveals that Intellexa’s Predator spyware has been used to target civil society members in Pakistan and potentially other countries, employing sophisticated zero-day exploits and various infection vectors. Despite international sanctions and public scrutiny, the company continues to develop and deploy invasive surveillance tools with possible human rights violations….

Read More

CrowdStrike tracked a China-nexus adversary dubbed WARP PANDA conducting persistent, stealthy intrusions against VMware vCenter and ESXi environments across U.S. legal, technology, and manufacturing organizations, deploying BRICKSTORM, JSP web shells, and two new Golang implants named Junction and GuestConduit. The actor exploited internet-facing edge device and vCenter vulnerabilities, tunneled traffic and…

Read More
Investigating Shai-Hulud: Inside the NPM Supply Chain Worm

Attackers exploited a GitHub Actions injection vulnerability in Nx’s workflow to steal an NPM publishing token, push malicious Nx packages, and use those packages to harvest credentials, SSH keys, and crypto wallets from developer systems. The campaign evolved into a self-replicating NPM supply-chain worm called Shai-Hulud that registers compromised hosts as self-hosted GitHub Actions runners and uses GitHub Discussions as a stealthy C2 channel. #ShaiHulud #Nx

Read More
DigitStealer MacOS Infostealer

DigitStealer is a macOS information stealer delivered as an unsigned DynamicLake.dmg that runs almost entirely in memory and abuses JavaScript for Automation (JXA) and AppleScript to harvest high-value data. It enforces geographic and Apple Silicon M2+ hardware checks, fetches four in-memory payloads (AppleScript stealer, two obfuscated JXA modules, and a LaunchAgent backdoor using DNS TXT for C2), and tampers with Ledger Live to enable seed-phrase exfiltration. #DigitStealer #LedgerLive

Read More
Arming Loki with jArvIs: How AI Is Powering Real-World Intrusions

Anthropic disclosed that a China-nexus group, tracked as GTG-1002, used an AI agent to run roughly 80–90% of a live cyber-espionage campaign that targeted about 30 entities and produced several confirmed intrusions. The operation chained thousands of small, routine-looking tasks through a Claude Code + MCP-based orchestrator, enabling high-speed reconnaissance, exploitation, credential abuse, lateral movement, and exfiltration. #GTG-1002 #PromptLock

Read More
Cybersecurity strategies to prioritize now

Microsoft Deputy CISO Damon Becknel outlines four immediate security priorities—basic cyber hygiene, modern standards and protocols, fingerprinting to identify bad actors, and increased collaboration—to reduce common, preventable online attacks. The post emphasizes practical actions like inventorying assets, enforcing phishing-resistant MFA, patching, network segmentation, DNS and SMTP hardening, and using fingerprinting and threat intelligence sharing to raise the cost for attackers. #Microsoft #EWS

Read More

Researchers observed a new variant of the ClayRat Android spyware that abuses Accessibility Services and Default SMS privileges to perform keylogging, automatic lock-screen unlocking, screen recording, persistent overlays, fake interactive notifications, notification harvesting, camera capture, and mass SMS/call functionality. The campaign distributed over 700 unique APKs via phishing domains and cloud hosting (Dropbox), impersonating services like YouTube and Car Scanner ELM while Zimperium reports on-device protections detect and mitigate these attacks. #ClayRat #Zimperium

Read More
Smile,Ā You’reĀ onĀ Camera:Ā AĀ LiveĀ Stream from InsideĀ Lazarus Group’sĀ IT WorkersĀ SchemeĀ 

North Korean APT Lazarus, specifically the Famous Chollima division, ran a large-scale social-engineering campaign recruiting remote IT workers to infiltrate U.S. finance, crypto/Web3, and other sectors for corporate espionage and regime funding. BCA LTD, NorthScan and ANY.RUN exposed the operation by engaging a recruiter, trapping operators in extended ANY.RUN sandboxes, and…

Read More