News

React2Shell under attack: RondoDox Botnet spreads miners and malware

  • Pierluigi Paganini--Securityaffairs.com
  • published date: 2026-01-01 14:31:42 UTC

RondoDox botnet exploits the critical React2Shell flaw (CVE-2025-55182) to infect vulnerable Next.js servers with malware and cryptominers. CloudSEK researchers warn that the RondoDox botnet is exploiting the critical React2Shell flaw (CVE-2025-55182) to drop…

React2Shell under attack: RondoDox Botnet spreads miners and malware CloudSEK researchers warn that the RondoDox botnet is exploiting the critical React2Shell flaw (CVE-2025-55182) to drop malware a… [+3082 chars]