Weekly Threat Intel TL;DR | Dec 6-12, 2025
0K THREAT INTEL TL;DR | Dec 6-12, 2025 | ⚡ 2-min read | 📖 Full detailed version →
🚨 CRITICAL THIS WEEK
1. React2Shell (CVE-2025-55182) - CVSS 10.0
- Unauthenticated RCE in React Server Components/Next.js
- Active exploitation since Dec 3, CISA KEV-listed
- Affects hundreds of thousands of web apps globally
- Action: Patch React 19.x/Next.js 15.x-16.x NOW
2. DeadLock Ransomware BYOVD - CVSS 9.0 (Est.)
- Abuses vulnerable Baidu Antivirus driver (CVE-2024-51324)
- Terminates EDR/AV before encryption
- Action: Block vulnerable drivers, enable OS driver blocklists
3. Makop Ransomware + GuLoader - CVSS 8.5 (Est.)
- RDP brute-force → GuLoader → privilege escalation → encryption
- Targeting Indian businesses, Brazil, Germany
- Action: Lock down RDP (VPN-only, MFA), patch Windows
🎯 BY THE NUMBERS
| Metric | Count |
|---|---|
| Critical CVEs | 5 |
| Major Ransomware Campaigns | 3 |
| Active Exploitation Confirmed | Yes (React2Shell, BYOVD) |
| Vulnerable IPs (Shadowserver) | Hundreds of thousands |
| Top Attack Vector | Exploit (React2Shell) + RDP |
📊 TOP MITRE ATT&CK TECHNIQUES
- T1190 - Exploit Public-Facing Application (React2Shell)
- T1133 - External Remote Services (Makop RDP)
- T1562 - Impair Defenses (DeadLock BYOVD, AV-killers)
- T1486 - Data Encrypted for Impact (Ransomware)
✅ ACTION ITEMS
Immediate (Next 24 Hours)
- Patch React/Next.js for CVE-2025-55182
- Block vulnerable Baidu AV driver
- Restrict RDP to VPN-only with MFA
- Deploy detection rules (see full brief)
This Week (24-72 Hours)
- Hunt for React2Shell exploitation on web servers
- Scan for BYOVD patterns on Windows endpoints
- Baseline RDP usage and block high-risk geos
- Validate offline backup integrity
🔗 QUICK LINKS
External Resources:
- CISA KEV Catalog
- CVE-2025-55182 Details
- React/Next.js Security Advisories
- Sigma Rules & Detection Guides
💡 KEY TAKEAWAY
React2Shell (CVE-2025-55182) is a CVSS 10.0 critical RCE affecting Next.js apps globally with active exploitation. Combined with aggressive ransomware using driver abuse and RDP attacks, this week demands immediate patching, RDP hardening, and detection deployment.
Prioritize React/Next.js patching above all else.
Follow 0K:
- Bluesky: @kelvinlomboy.bsky.social
- LinkedIn: @kelvinlomboy
- GitHub: @0K-cool
Disclaimer:
This TL;DR is a summary for quick reference. For complete threat intelligence, IOCs, detection rules, and detailed analysis, read the full briefing.
Threat Intelligence: Based on open-source intelligence current as of the reporting date. Organizations should validate findings with internal telemetry before making security decisions.
Detection Rules: All rules are experimental. Test in non-production before deployment.
0K assumes no liability for decisions made based on this report.