Threats · 56 days ago
The useful shift is not that React2Shell was exploited. It is that China-nexus crews moved from fresh RCE to credential theft in less than a day, which leaves defenders with less time than many teams need just to confirm exposure. Once the code execution lands, the fight shifts from patching a flaw to containing an identity compromise.
CrowdStrike tied that pace to Vault Panda and Genesis Panda, who used the React2Shell bug in React Server Components and Next.js applications and then dropped RATs for post-exploit credential harvesting. The same report says 88% of publicly disclosed exploited flaws in H1 2026 were hit within 48 hours, so disclosure-day and secret hygiene now belong in the same response window.
1 source covering this story
Chinese Threat Actors Weaponize New Vulnerabilities in Under a Day
Chinese actors exploited the critical React2Shell exploit inside a day, while 88% of exploited vulnerabilities in H1 2026 were compromised within 48 hours of disclosure
Part of the PlainSec briefing for 2026-08-04