A ransomware gang exploited the critical React2Shell vulnerability (CVE-2025-55182) to gain initial access to corporate networks and deployed the file-encrypting malware less than a minute later.
If you have a fediverse account, you can quote this note from your own instance. Search https://infosec.exchange/users/BleepingComputer/statuses/115735777072036234 on your instance and quote it. (Note that quoting is not supported in Mastodon.)
RE: https://infosec.exchange/@BleepingComputer/115735777072036234
I will never forgive the security community for not naming this vulnerability "Reactor Meltown".
