Title: Large-Scale Credential Theft Campaign Targets Vulnerable Apps
Hackers have launched a widespread campaign to steal sensitive credentials using the React2Shell vulnerability, affecting vulnerable Next.js applications. At least 766 hosts across various cloud providers have been compromised, leading to the theft of critical information like AWS credentials, SSH keys, and API tokens.
The attackers utilized a framework called NEXUS Listener to automate the extraction of sensitive data. This operation allows hackers to view statistics on the stolen credentials and the number of compromised hosts in real time.
The impact of this breach could be severe, allowing attackers to take over cloud accounts and potentially launch supply chain attacks. Victims may also face regulatory repercussions due to privacy violations.
To mitigate risks, experts recommend applying security updates for React2Shell, auditing server-side data, and rotating all credentials. Ensuring secure configurations and implementing strict access controls are also vital.
Risk Level: High
Source: View Original Report
