U.S. CISA adds a Meta React Server Components flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 31, 19:34 UTC · Dec 31, 2025Exploit / PoC in the wildCVE-2025-5518260
AWS: China-linked threat actors weaponized React2Shell hours after disclosureSecurity Affairs·Dec 8, 13:37 UTC · Dec 8, 2025Threat actor in the wildCVE-2025-55182CVE-2025-133860
North Korean Hackers Deploy 197 npm Packages to Spread Updated OtterCookie MalwareThe Hacker News·Nov 28, 16:18 UTC · Nov 28, 2025Malware42
Rspack npm Packages Compromised with Crypto Mining Malware in Supply Chain AttackThe Hacker News·Dec 21, 08:59 UTC · Dec 21, 2024Malware42
North Korean Hackers Suspected in New Wave of Malicious npm PackagesThe Hacker News·Aug 17, 13:38 UTC · Aug 17, 2023Malware42
Multiple Chinese APTs are attacking European targets, EU cyber agency warnsThe Record·Mar 28, 15:27 UTC · Mar 28, 2023Ransomware57
iOS exploit chain deploys LightSpy featureKaspersky Securelist·Mar 26, 17:32 UTC · Mar 26, 2020Exploit / PoC57