Discussion about this post

User's avatar
Neural Foundry's avatar

Solid roundup of teh threat landscape right now! The React2Shell situation is wild because the velocity of exploitation after public disclosure is something we rarley see outside of major enterprise stacks. I spent a few months pen-testing Node applications last year and the attack surface on improperly secured RSC endpoints was already kind of ridiculous even before this CVE dropped, so now its basically game over for anyone running defaults.

No posts

Ready for more?