Dec 09, 2025 Email 1: Subject: Risky Bulletin: APTs go after the React2Shell vulnerability within hours Summary: – At least two Chinese APT groups, Earth Lamia and Jackpot Panda, have exploited the newly disclosed React2Shell vulnerability (CVE-2025-55182) in the React Server Components framework. – Attacks began within hours of disclosure.
