Kubernetes Attacks Spike as React2Shell Enables Cloud Identity Theft
Attackers are exploiting a React Server Components vulnerability (CVE-2025-55182) not just to break out of containers, but to steal Kubernetes service-account tokens. This identity theft lets attackers move beyond the container to access cloud backend infrastructure through legitimate credentials. Unit 42 reports a 282% year-over-year increase in Kubernetes token theft, with 78% of activity targeting the IT sector. The December surge in cloud-service attacks directly links to this vulnerability, showing active exploitation shortly after its disclosure. Standard container hardening misses the real risk: attackers leverage stolen Kubernetes identities to pivot across cloud services, expanding their reach without traditional container escape. This pattern demands urgent attention for any Kubernetes-facing web app using React Server Components, as the blast radius extends from app-layer bugs to cloud infrastructure compromise.