0K THREAT INTEL TL;DR | Dec 6-12, 2025 | ⚡ 2-min read | 📖 Full detailed version →


🚨 CRITICAL THIS WEEK

1. React2Shell (CVE-2025-55182) - CVSS 10.0

  • Unauthenticated RCE in React Server Components/Next.js
  • Active exploitation since Dec 3, CISA KEV-listed
  • Affects hundreds of thousands of web apps globally
  • Action: Patch React 19.x/Next.js 15.x-16.x NOW

2. DeadLock Ransomware BYOVD - CVSS 9.0 (Est.)

  • Abuses vulnerable Baidu Antivirus driver (CVE-2024-51324)
  • Terminates EDR/AV before encryption
  • Action: Block vulnerable drivers, enable OS driver blocklists

3. Makop Ransomware + GuLoader - CVSS 8.5 (Est.)

  • RDP brute-force → GuLoader → privilege escalation → encryption
  • Targeting Indian businesses, Brazil, Germany
  • Action: Lock down RDP (VPN-only, MFA), patch Windows

🎯 BY THE NUMBERS

Metric Count
Critical CVEs 5
Major Ransomware Campaigns 3
Active Exploitation Confirmed Yes (React2Shell, BYOVD)
Vulnerable IPs (Shadowserver) Hundreds of thousands
Top Attack Vector Exploit (React2Shell) + RDP

📊 TOP MITRE ATT&CK TECHNIQUES

  1. T1190 - Exploit Public-Facing Application (React2Shell)
  2. T1133 - External Remote Services (Makop RDP)
  3. T1562 - Impair Defenses (DeadLock BYOVD, AV-killers)
  4. T1486 - Data Encrypted for Impact (Ransomware)

✅ ACTION ITEMS

Immediate (Next 24 Hours)

  • Patch React/Next.js for CVE-2025-55182
  • Block vulnerable Baidu AV driver
  • Restrict RDP to VPN-only with MFA
  • Deploy detection rules (see full brief)

This Week (24-72 Hours)

  • Hunt for React2Shell exploitation on web servers
  • Scan for BYOVD patterns on Windows endpoints
  • Baseline RDP usage and block high-risk geos
  • Validate offline backup integrity

📖 Read Full Detailed Brief →

External Resources:


💡 KEY TAKEAWAY

React2Shell (CVE-2025-55182) is a CVSS 10.0 critical RCE affecting Next.js apps globally with active exploitation. Combined with aggressive ransomware using driver abuse and RDP attacks, this week demands immediate patching, RDP hardening, and detection deployment.

Prioritize React/Next.js patching above all else.


Follow 0K:


Disclaimer:

This TL;DR is a summary for quick reference. For complete threat intelligence, IOCs, detection rules, and detailed analysis, read the full briefing.

Threat Intelligence: Based on open-source intelligence current as of the reporting date. Organizations should validate findings with internal telemetry before making security decisions.

Detection Rules: All rules are experimental. Test in non-production before deployment.

0K assumes no liability for decisions made based on this report.