China-nexus groups exploit vulnerabilities within 24 hours, CrowdStrike reports
This digest was compiled by AI from multiple sources — links to the originals are below.

China-nexus threat groups are exploiting newly disclosed critical vulnerabilities within 24 hours, according to a CrowdStrike report released August 3. The groups Vault Panda and Genesis Panda targeted the React2Shell flaw to deploy remote access trojans and steal credentials, even as 88% of exploits observed in early 2026 occurred within 48 hours of disclosure.
React2Shell Exploitation
The critical React2Shell vulnerability in React Server Components and Next.js was disclosed in December 2025 and patched concurrently. CrowdStrike observed multiple threat actors exploiting it, but China-nexus Vault Panda (UNC6588) and Genesis Panda (REF0657) were the fastest, deploying tools to harvest credentials and execute remote code. Their speed demonstrates proactive monitoring and pre-staging of malicious tools.
Shrinking Patch Windows
CrowdStrike's 2026 Threat Hunting Report found that 88% of publicly disclosed vulnerability exploits in the first half of 2026 began within 48 hours. This represents a 42% year-over-year rise in zero-day exploitation from 2024 to 2025. The firm notes that frontier AI models, including Anthropic's Mythos and OpenAI's GPT-5.4-Cyber, are likely increasing the volume of disclosed flaws, further compressing the time defenders have to patch.
Identity Attack Surge
The report highlights a doubling in vishing-based intrusions as an initial access vector in H1 2026 compared to H1 2025. Financially motivated actors are increasingly using LLMJacking to compromise corporate AI platforms, as seen in one campaign that sent nearly 200,000 API requests in two minutes after gaining elevated cloud access. The technique aims to cause financial harm by sabotaging AI services.
What's Next
CrowdStrike warns that the integration of frontier AI into vulnerability research will likely shorten exploitation timelines further. It remains unclear how organizations can adapt to the accelerating pace of attacks.
1 source
China-nexus groups exploit vulnerabilities within 24 hours, CrowdStrike reports






