React2Shell flaw (CVE-2025-55182) exploited for remote code execution
The availability of exploit code will likely lead to more widespread opportunistic attacks
Tags: Threat Research, Featured, vulnerability, react2shell
From 24 to 28 November 2025, Europol supported an action week conducted by law enforcement authorities from Switzerland and Germany in Zurich, Switzerland. The operation focused on taking down the illegal cryptocurrency mixing service ‘Cryptomixer’, which is suspected of facilitating cybercrime and money laundering. Three servers were seized in Switzerland, along with the cryptomixer.io domain…….
Andy Dossett reports: A network security incident crippled Bartlesville Public Schools’ internet systems, forcing the district to cancel state testing and prompted an investigation into the scope of the breach. Granger Meador, executive director of technology and communications for the district, confirmed May 1 that the disruption rendered many of the district’s computer systems inoperable….
A threat actor that’s known to share overlaps with a hacking group called YoroTrooper has been observed targeting the Russian public sector with malware families such as FoalShell and StallionRAT. Cybersecurity vendor BI.ZONE is tracking the activity under the moniker Cavalry Werewolf. It’s also assessed to have commonalities with clusters tracked as SturgeonPhisher, Silent Lynx,…
From the We-Wish-This-Was-An-April-Fools-Joke-But-It’s-Not department: It appears that another plastic surgery entity has fallen prey to a cyberattack, and once again, a lot of sensitive patient data has been leaked. Paul Vitenas, Jr., M.D., F.A.C.S. is the founder of Vitenas Cosmetic Surgery, Mirror Mirror Beauty Boutique, and the Houston Surgery Center in Texas. On March 5, …
Michael Kan reports: National Public Data, a website infamous for its role in leaking millions of Social Security numbers last year, has returned with the ability to look up anyone’s personal information. The site shut down in December amid a wave of lawsuits against parent company Jericho Pictures after a breach exposed an estimated 272 million unique SSNs and……
NL Times reports: A large-scale cyberattack hit multiple Dutch municipalities and provinces on Monday morning, rendering the websites of more than twenty local governments inaccessible for several hours. The attack, claimed by the pro-Russian hacker group NoName, caused significant disruption but did not compromise critical infrastructure or steal any data, according to AD. The group, which has…