CVE
CVE-2025-55182
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
Exploitation IoCs 36
Domain c2[.]saintpetersburgresident[.]ru
Domain dysphoria[.]androiddebugbridge[.]su
Domain ethereum[.]ens
Domain i[.]peer4you[.]net
Domain jerusalem[.]androiddebugbridge[.]su
Domain kieron[.]androiddebugbridge[.]su
Domain login[.]trees4sale[.]net
Domain node[.]androiddebugbridge[.]su
Domain o[.]peer4you[.]net
Domain peer[.]saintpetersburgresident[.]ru
Domain solana[.]sns
Domain telaviv[.]androiddebugbridge[.]su
Domain wow[.]androiddebugbridge[.]su
Domain www[.]trees4sale[.]net
Filename libdalvikengine.so
GitHub Repo 24carnforth2merseyside.sol
GitHub Repo burrberry.eth
GitHub Repo m3rnbvs5d.eth
GitHub Repo ukranianhorseriding.eth
SHA-1 25081bdec05f64eb4f313420c82d8de957e30026
SHA-1 73651c02b29f1c07e3177e86c967fc45e9f30f0f
SHA-1 8db6c78533c176f13b61405cdc3f8fad703325f1
SHA-1 955ff909972958098f0d4a06bcc4d6b9eea90449
SHA-1 9c1716d770ea69e8e1418d96d52222396ecb4362
SHA-1 a3b9575897c16cbf6afe3af1aa8b55171ea6edf9
SHA-1 b0782a9d6eef2ce02f734a6e5e1d8e0f9a2b65be
SHA-1 b7faa44ab0772047a8581bbfdd9c561e28fc66de
SHA-1 c1bedea261f325441fb9a75c50b11d0c8fb01ac6
SHA-1 dcea71b9ab9de8efca301de9e2f7bf11c7132364
SHA-1 df510f6f69a5c149c216c7b3accc4f460d8cf363
SHA-1 e7e1694162639ed587625432a79cfaa49f560d11
IP 144[.]31[.]38[.]215
IP 217[.]60[.]195[.]160
IP 76[.]164[.]203[.]171
IP 78[.]153[.]155[.]152
IP 92[.]42[.]100[.]131
MITRE ATT&CK TTPs 28
T1001.002 T1021.004 T1059 T1059.001 T1059.004 T1070.001 T1071.001 T1078 T1082 T1090 T1098 T1110 T1133 T1190 T1203 T1210 T1211 T1218 T1485 T1566 T1569 T1570 T1571 T1572 T1589 T1595 T1599 T1650
Steganography
Command And Control
SSH
Lateral Movement
Command and Scripting Interpreter
Execution
PowerShell
Execution
Unix Shell
Execution
Clear Windows Event Logs
Defense Evasion
Web Protocols
Command And Control
Valid Accounts
Defense Evasion
System Information Discovery
Discovery
Proxy
Command And Control
Account Manipulation
Persistence
Brute Force
Credential Access
External Remote Services
Persistence
Exploit Public-Facing Application
Initial Access
Exploitation for Client Execution
Execution
Exploitation of Remote Services
Lateral Movement
Exploitation for Defense Evasion
Defense Evasion
System Binary Proxy Execution
Defense Evasion
Data Destruction
Impact
Phishing
Initial Access
System Services
Execution
Lateral Tool Transfer
Lateral Movement
Non-Standard Port
Command And Control
Protocol Tunneling
Command And Control
Gather Victim Identity Information
Reconnaissance
Active Scanning
Reconnaissance
Network Boundary Bridging
Defense Evasion
Acquire Access
Resource Development
Source Articles
僵尸网络新秀:Dysphoria 演进与深度技术分析
Dysphoria 是一个自2026年初开始活跃的新兴僵尸网络家族,已控制超过20万台设备。该僵尸网络通过弱口令爆破和多个已知IoT漏洞进行传播,包括CVE-2017-17215、CVE-2020-8515等。其技术演进迅速,引入了基于以太坊ENS和Solana SNS区块链域名的C2隐蔽解析机制,并将受感染主机转化为C2中继节点,增强了抗打击能力。最新变种使用自定义RC4加密算法、UPnP内网穿透和动态中继架构,具备强大的DDoS攻击能力,宣称可达到4Tbps,并已实现商业化攻击服务运营。
static-urls
New Dysphoria DDoS botnet spreads to 200k devices worldwide
The Dysphoria DDoS botnet has infected approximately 200,000 devices worldwide by exploiting weak credentials and known vulnerabilities in IoT devices. It evolved from 'jackskid' and 'fbot' malware, incorporating a blockchain-based command-and-control mechanism using Ethereum ENS and Solana SNS domains for resilience. The botnet conducts DDoS attacks and can transform infected devices into network proxies, leveraging UPnP to expose internal services. Its operators claim a maximum attack capacity of 4 Tbps, promoting the service on a clearnet website as a stress-testing tool.
bleeping-computer Jul 27, 2026
Next.js moves to scheduled security releases
Next.js is transitioning to a scheduled security release model to address vulnerabilities in a predictable and coordinated manner, replacing ad-hoc patching. This change follows high-severity incidents like React2Shell (CVE-2025-55182), a critical remote code execution flaw in React Server Components that was widely exploited. The new program enables advance notice of patches, allowing organizations time to plan upgrades and implement mitigations. Vercel cites increasing vulnerability discovery rates due to AI-assisted tools as a driver for more frequent and structured releases.
socket-dev
No Manners Here: The Ruthless Rise of The Gentlemen Ransomware
The Gentlemen, also known as Storm-2697, is a Ransomware-as-a-Service (RaaS) operation active since July 2025, believed to have evolved from the Qilin RaaS affiliate ArmCorp. They offer affiliates an unusually high 90% ransom payout, contributing to rapid growth, with over 580 victims claimed across 77 countries by mid-2026. The group uses diverse initial access methods, custom tools like the 'GentleKiller' EDR killer, and exploits vulnerabilities in edge devices and protocols to target enterprises, particularly in manufacturing.
unit42 Jul 10, 2026