Notícias
Vulnerabilidades
6 de dezembro de 2025
React2Shell flaw exploited to breach 30 orgs, 77k IP addresses vulnerable
Over 77,000 Internet-exposed IP addresses are vulnerable to the critical React2Shell remote code execution flaw (CVE-2025-55182), with researchers now confirming that attackers have already compromised over 30 organizations across multiple sectors. [...]
5 de dezembro de 2025
Barracuda Application Protection safeguards against critical React and Next.js vulnerabilities
Two critical remote code execution (RCE) vulnerabilities—CVE-2025-55182 and CVE-2025-66478—impact applications built on React and Next.js, enabling attackers to execute arbitrary code without authentication. Barracuda Application Protection, including Barracuda WAF and WAF-as-a-Service, offers automatic safeguards against these threats through real-time signature updates and layered defenses.
4 de dezembro de 2025
Max-severity vulnerability in React, Node.js patched, update ASAP (CVE-2025-55182)
A critical vulnerability (CVE-2025-55182) in React Server Components (RSC) may allow unauthenticated attackers to achieve remote code exection on the application server, the React development team warned on Wednesday. The maximum-severity vulnerability was privately reported by Lachlan Davidson and has been fixed. At this moment, there are no public reports of it being exploited by attackers and no confirmed public PoC exploits (for now). Nevertheless, affected users have been advised to upgrade to a non-vulnerable … More → The post Max-severity vulnerability in React, Node.js patched, update ASAP (CVE-2025-55182) appeared first on Help Net Security.
4 de dezembro de 2025
NCSC's 'Proactive Notifications' warns orgs of flaws in exposed devices
The UK's National Cyber Security Center (NCSC) announced the testing phase of a new service called Proactive Notifications, designed to inform organizations in the country of vulnerabilities present in their environment. [...]
3 de dezembro de 2025
Developers scramble as critical React flaw threatens major apps
The open-source code library is one of the most extensively used application frameworks. Wiz found vulnerable versions in around 39% of cloud environments. The post Developers scramble as critical React flaw threatens major apps appeared first on CyberScoop.
3 de dezembro de 2025
Patch Management Procedure: Building a Secure and Efficient Update Process
Reading Time: 6 minutes Cyber threats are growing more advanced every year, and unpatched systems remain one of the biggest reasons organizations suffer data breaches. In fact, many attacks rely on known vulnerabilities that could have been prevented with proper updates. That's why having a strong patch management procedure is essential for IT managers, cybersecurity teams, and business leaders.... The post Patch Management Procedure: Building a Secure and Efficient Update Process appeared first on Comodo News and Internet Security Information.
