Critical

Attacks pinned to critical React2Shell defect surge, surpass 50 confirmed victims

CyberScoop
Actively Exploited

Overview

Researchers have identified a significant surge in attacks linked to a vulnerability in React2Shell, with more than 50 confirmed victims to date. This issue stems from a critical defect that has left many systems exposed, as reports indicate that about half of these vulnerable instances remain unpatched. The rapid exploitation of this flaw underscores the urgency for affected organizations to take immediate action to secure their systems. Companies using React2Shell need to prioritize updates and patch deployments to mitigate these risks. Failure to address this vulnerability could lead to more widespread damage and data breaches as attackers continue to exploit the flaw in the wild.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: React2Shell
  • Action Required: Organizations should apply the latest patches and updates for React2Shell as soon as possible to protect against exploitation.
  • Timeline: Ongoing since recent weeks

Original Article Summary

Researchers warn that half of the exposed vulnerable instances remain unpatched as in-the-wild exploitation grows rapidly. The post Attacks pinned to critical React2Shell defect surge, surpass 50 confirmed victims appeared first on CyberScoop.

Impact

React2Shell

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Ongoing since recent weeks

Remediation

Organizations should apply the latest patches and updates for React2Shell as soon as possible to protect against exploitation.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Exploit, Vulnerability, Patch, and 1 more.

Related Coverage

Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft

Security Affairs

The extortion group FulcrumSec claims to have stolen 86GB of data from the Manchester Airports Group (MAG) after discovering exposed API credentials in client-side JavaScript. This breach affects customers of Manchester, London Stansted, and East Midlands airports. MAG reported the data breach on August 27, which has raised concerns about the security of sensitive information related to airport operations and passenger data. The exposure of API credentials signifies a serious vulnerability that could lead to further exploitation. As the incident unfolds, it highlights the need for companies to prioritize secure coding practices to prevent similar breaches in the future.

Aug 30, 2026

FulcrumSec claims Manchester Airports hack, theft of 86 GB of data

BleepingComputer

FulcrumSec has announced that it successfully hacked into the Manchester Airports Group, stealing 86 GB of sensitive data. This breach reportedly includes detailed information about travelers, including personal details, booking history, and travel itineraries, which go beyond what the airport initially revealed. BleepingComputer was able to verify at least one of the compromised traveler records, highlighting the seriousness of the breach. The implications of this incident are significant, as it raises concerns about the security of personal data held by large organizations like airports. Travelers and customers of Manchester Airports Group should be vigilant about their personal information and any potential impacts from this data theft.

Aug 30, 2026

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

BleepingComputer

Anthropic has issued a warning to users of its AI assistant, Claude, regarding a new infostealer malware threat. This malware compromises users' computers, stealing active login sessions for Claude and allowing attackers to access these accounts and consume their usage. The situation poses a significant risk as it could lead to unauthorized access and potential data breaches for affected users. The company emphasizes the importance of securing personal devices to prevent such attacks. Users are advised to check for malware on their systems and take appropriate security measures to protect their accounts.

Aug 30, 2026

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 112

Security Affairs

The latest Security Affairs Malware newsletter reports on a campaign named Operation QUICSILVER, which is attributed to a Chinese-linked actor targeting diplomats in Myanmar. This operation involves the use of a Go backdoor that is delivered via VHD files. In addition, the newsletter discusses the emergence of FTP banners as a new method for delivering remote access Trojans (RATs). The report also touches on the evolving landscape of AI-enabled malware, highlighting changes from brand abuse to more sophisticated attacks. These developments indicate a growing trend in cyber threats that exploit both social engineering and advanced technology, affecting diplomatic communications and potentially compromising sensitive information.

Aug 30, 2026

Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch

Security Affairs

PaperCut servers, widely used for print management in schools, hospitals, and offices, are currently facing active attacks. A significant 47% of installations are still running unpatched versions that are vulnerable to a remote code execution flaw. This vulnerability allows attackers to execute code without prior authentication, raising serious security concerns. Researchers from Huntress have identified that these attacks are not just theoretical; they are being actively exploited against real customers. It's critical for organizations using PaperCut to address this issue promptly to protect sensitive data and maintain operational integrity.

Aug 30, 2026

Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited

Help Net Security

Last week, the Shadowserver Foundation reported that at least 274 Zimbra servers exposed to the internet have been compromised due to a vulnerability identified as CVE-2026-73570. The attackers behind these breaches remain unknown, but the exploitation of this flaw raises serious concerns for organizations using Zimbra, a widely used collaboration platform. This incident highlights the risks associated with unpatched software, as these servers could be exploited for data theft or further attacks. Companies running Zimbra should take immediate action to secure their systems to prevent similar compromises from occurring.

Aug 30, 2026