React2Shell Exploitation: Global Cyber Threat Targets React JavaScript Library
The Register
|
Contributed by: Drex DeFord
Summary
Google has raised an alarm regarding a critical vulnerability, CVE-2025-55182, in the React JavaScript library, which allows unauthorized code execution by attackers. Exploited by state-sponsored groups from China and Iran, as well as cybercriminals, this flaw has been linked to the deployment of malicious backdoors and cryptocurrency miners across over 50 organizations in various sectors. The swift exploitation of this vulnerability, disclosed by React maintainers on December 3, underscores significant cybersecurity risks and the urgent need for healthcare technology professionals to enhance their defenses against such threats. Addressing this issue is crucial for safeguarding sensitive healthcare data and infrastructure from escalating cyberattacks.