Massive Breach: Hackers Target 766 Next.js Hosts via CVE-2025-55182

Date:

Massive Credential Harvesting Attack Targets Next.js Applications

A significant cybersecurity incident has emerged, affecting numerous organizations worldwide. Cybercriminals are exploiting a critical vulnerability in Next.js applications, identified as CVE-2025-55182, to launch a credential harvesting campaign. This attack has compromised at least 766 hosts, allowing hackers to steal sensitive data such as database credentials, API keys, and SSH private keys.

The malicious group, tracked as UAT-10608, is using automated scripts to extract and exfiltrate credentials, which are then stored in a web-based interface called NEXUS Listener. This tool provides a detailed overview of stolen information, making it easier for attackers to analyze their gains.

Organizations using Next.js are particularly at risk. To mitigate exposure, experts recommend auditing environments, enforcing strict access controls, enabling secret scanning, and regularly rotating credentials.

Given the scale and sensitivity of the data compromised, this incident is rated High risk.

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

Critical PHP Object Injection Vulnerability Found in GiveWP Plugin

A recently discovered vulnerability in the GiveWP plugin poses...

AI Advances Strengthen Cybersecurity: Wordfence Unveils Critical Vulnerability Discovery

Wordfence has revealed significant advancements in its incorporation of...

Critical Unauthenticated Account Takeover Vulnerability Found in TranslatePress Plugin

On August 11, 2026, a significant security vulnerability was...

Hackers Target WordPress Sites in miniOrange Authentication Bypass Attacks

In recent weeks, hackers have escalated their attacks on...