mimile
Back to feed
This event is part of a larger story
Франция, Казахстан, Польша: кибератаки раскрыли данные сотен тысяч
Read briefing

China-nexus groups exploit vulnerabilities within 24 hours, CrowdStrike reports

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

China-nexus groups exploit vulnerabilities within 24 hours, CrowdStrike reports

China-nexus threat groups are exploiting newly disclosed critical vulnerabilities within 24 hours, according to a CrowdStrike report released August 3. The groups Vault Panda and Genesis Panda targeted the React2Shell flaw to deploy remote access trojans and steal credentials, even as 88% of exploits observed in early 2026 occurred within 48 hours of disclosure.

React2Shell Exploitation

The critical React2Shell vulnerability in React Server Components and Next.js was disclosed in December 2025 and patched concurrently. CrowdStrike observed multiple threat actors exploiting it, but China-nexus Vault Panda (UNC6588) and Genesis Panda (REF0657) were the fastest, deploying tools to harvest credentials and execute remote code. Their speed demonstrates proactive monitoring and pre-staging of malicious tools.

Shrinking Patch Windows

CrowdStrike's 2026 Threat Hunting Report found that 88% of publicly disclosed vulnerability exploits in the first half of 2026 began within 48 hours. This represents a 42% year-over-year rise in zero-day exploitation from 2024 to 2025. The firm notes that frontier AI models, including Anthropic's Mythos and OpenAI's GPT-5.4-Cyber, are likely increasing the volume of disclosed flaws, further compressing the time defenders have to patch.

Identity Attack Surge

The report highlights a doubling in vishing-based intrusions as an initial access vector in H1 2026 compared to H1 2025. Financially motivated actors are increasingly using LLMJacking to compromise corporate AI platforms, as seen in one campaign that sent nearly 200,000 API requests in two minutes after gaining elevated cloud access. The technique aims to cause financial harm by sabotaging AI services.

What's Next

CrowdStrike warns that the integration of frontier AI into vulnerability research will likely shorten exploitation timelines further. It remains unclear how organizations can adapt to the accelerating pace of attacks.

1 source

China-nexus groups exploit vulnerabilities within 24 hours, CrowdStrike reports