【安全圈】微软修复三处0Day漏洞:云文件驱动提权至SYSTEM与Copilot远程代码执行风险
关键词漏洞漏洞概览微软在2025年12月的"补丁星期二"发布了年度收官安全更新,共修复其生态系统中72个漏洞,
A novel, highly sophisticated malware strain targeting vulnerable React Server Components, signaling a significant evolution in how state-sponsored threat actors are exploiting the critical React2Shell vulnerability disclosed just days earlier. On December 5, 2025, just two days after the disclosure of the maximum-severity vulnerability CVE-2025-55182 (dubbed “React2Shell”), the Sysdig Threat Research Team (TRT) discovered a […]
The post North Korean Hackers Exploit React2Shell Vulnerability in the Wild to Deploy EtherRAT appeared first on Cyber Security News.