Skip to main content
Cyber Week Sale - Get 40% off Vantage
Published loading...Updated

AWS: Beijing-Linked Hackers Hammering Max-Severity React Bug

China-linked groups Earth Lamia and Jackpot Panda exploit React2Shell vulnerability to execute remote JavaScript on thousands of servers, with 39% of cloud environments vulnerable, researchers say.

  • On December 3, 2025, Amazon Web Services reported China-linked Earth Lamia and Jackpot Panda exploited React2Shell, an insecure deserialization flaw in the React Server Components 'Flight' protocol allowing unauthenticated remote JavaScript execution.
  • Proof-of-Concept exploits appeared rapidly, including fake variants, and React and Next.js maintainers issued updates though thousands of dependent projects remain exploitable by default.
  • AWS observed repeated payload attempts and Linux commands , while attacking clusters shared anonymization infrastructure, complicating tracking amid iterative manual testing.
  • Wiz researchers found 39% of cloud environments vulnerable to React2Shell attacks, targeting financial services, logistics, retail, IT companies, universities, government sectors in Latin America, the Middle East, Southeast Asia; Assetnote released a scanner on GitHub.
  • Earth Lamia focuses on exploiting web application vulnerabilities while Jackpot Panda targets East and Southeast Asia to collect intelligence, and CVE-2025-66478 was rejected as a duplicate of CVE-2025-55182 despite exploits confirmed by Rapid7 researcher Stephen Fewer and Elastic Security's Joe Desimone.
Insights by Ground AI

15 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

Help Net Security broke the news in on Thursday, December 4, 2025.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal