Connect with us

Tech

Cyber teams on alert as React2Shell exploitation spreads | Computer Weekly

Published

on

Cyber teams on alert as React2Shell exploitation spreads | Computer Weekly


A remote code execution (RCE) vulnerability in the React JavaScript library, which earlier today caused disruption across the internet as Cloudflare pushed mitigations live on its network, is now being exploited by multiple threat actors at scale, according to reports.

Maintained by Meta, React is an open source resource designed to enable developers to build user interfaces (UIs) for both native and web applications.

The vulnerability in question, assigned CVE-2025-55182 and dubbed React2Shell by the cyber community, is a critically-scored pre-authentication RCE flaw in versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 of React Server Components that exploits a flaw in how they decode payloads sent to React Function Endpoints.

This means that by crafting a malicious HTTP request to a Server Function endpoint, this means a threat actor could gain the ability to run arbitrary code on the target server.

It was added to the US’ Cybersecurity and Infrastructure Security Agency’s (CISA’s) catalogue on Friday 5 December, and according to Amazon Web Services (AWS) CISO and vice president of security engineering, C.J. Moses, the chief culprits behind the rapid exploitation are thought to be China-nexus threat actors.

Moses cautioned that China’s habit of running shared, large-scale anonymisation infrastructure for multiple state-backed threat actors made definitive attribution challenging, however, following disclosure on Wednesday 3 December, groups tracked as Earth Lamia and Jackpot Panda were observed taking advantage of React2Shell.

“China continues to be the most prolific source of state-sponsored cyber threat activity, with threat actors routinely operationalising public exploits within hours or days of disclosure,” he wrote.

“Through monitoring in our AWS MadPot honeypot infrastructure, Amazon threat intelligence teams have identified both known groups and previously untracked threat clusters attempting to exploit CVE-2025-55182.”

Earth Lamia is well-known for exploiting web application vulnerabilities against organisations primarily located in Latin America, the Middle East, and Southeast Asia, with a particular focus on educational institutions, financial services organisations, government bodies, IT companies, logistics firms, and retailers.

Jackpot Panda, according to AWS, targets its activity at entities in East and Southeast Asia, with its operations aligning to China’s goals relating to corruption and domestic security.

Massive attack

With reports suggesting that there may be over 950,000 servers running vulnerable frameworks such as React and Next.js, Radware threat researchers warned of a massive potential attack surface.

React and Next.js are both well-used thanks to their efficiency and flexibility, while robust ecosystems make them a default choice for many developers – and as such they are found under the bonnet everywhere, from mobile apps and consumer-facing websites to enterprise-grade platforms, said Radware.

“This widespread reliance means a single critical flaw can have cascading consequences for a significant portion of modern web infrastructure,” the Radware team said. “A substantial number of applications across public and private clouds are immediately exploitable, necessitating urgent and widespread action.”

Michael Bell, founder and CEO of Suzu Labs, a penetration testing and AI security specialist, said that hours from disclosure to active exploitation by nation-state actors was the new normal, and matters would likely get worse.

“China-nexus groups have industrializsd their vulnerability response: they monitor disclosures, grab public PoCs – even broken ones – and spray them at scale before most organisations have finished reading the advisory,” he said.

“AWS’s report showing attackers debugging exploits in real-time against honeypots demonstrates this isn’t automated scanning; it’s hands-on-keyboard operators racing to establish persistence before patches roll out.

“With AI tools increasingly capable of parsing vulnerability disclosures and generating exploit code, expect the window between disclosure and weaponization to shrink from hours to minutes,” said Bell.

He added that the earlier Cloudflare outage in service of an emergency patch “tells you everything about the severity calculus here”.



Source link

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Tech

A Brain Implant for Depression Is About to Be Tested in Humans

Published

on

A Brain Implant for Depression Is About to Be Tested in Humans


The latest brain-computer interface could help people recover from severe depression. Motif Neurotech announced Monday that the US Food and Drug Administration has approved a human study to trial the company’s blueberry-sized brain implant that sits in the skull and delivers electrical stimulation to treat depression.

The Houston-based startup, founded in 2022, is part of a budding industry pursuing technology to read and interpret brain signals. While other companies exploring similar technology, like Elon Musk’s Neuralink, Paradromics, and Synchron, are developing devices to enable paralyzed people to communicate and use computers, Motif is aiming to ease depression in people who have not benefited from medication.

The company’s device is implanted in the skull just above the dura, the brain’s protective membrane. It targets the central executive network, a part of the brain that is responsible for high-level cognitive functions and is underactive in major depressive disorder. The implant emits specific patterns of stimulation to turn “on” this network.

Motif’s device would allow patients to receive therapeutic brain stimulation at home. “Through frequent electrical stimulation, we think we can drive that neuroplasticity that creates stronger connectivity within the central executive network for patients with depression, so that they can get out of bed in the morning, call their friends, go to the gym,” says Jacob Robinson, Motif’s cofounder and CEO.

Courtesy of Motif

Electrical stimulation has been used for decades to treat depression, and Motif’s approach is just the latest iteration. Electroconvulsive or “shock” therapy began in the 1930s and is still used today in cases where patients don’t benefit from antidepressants. Deep brain stimulation, which involves surgically implanting electrodes into the brain, is occasionally used experimentally but is not FDA approved. A much milder form of stimulation known as transcranial magnetic stimulation, or TMS, was approved in 2008. While it can be highly effective, it typically requires a lengthy treatment regimen of five treatments a week for six weeks.

A study from 2021 found that during a 12-month period in the United States, nearly 9 million adults were undergoing treatment for major depressive disorder, and of those, almost 3 million were considered to have treatment-resistant depression, when symptoms do not improve after at least two, and often more, antidepressant medications.

Motif’s device can be implanted in a 20-minute outpatient procedure without the need for brain surgery. It’s powered by wireless magnetoelectric technology that Robinson developed while at Rice University and is charged with a baseball cap that patients will wear when receiving the stimulation.



Source link

Continue Reading

Tech

The Man Behind AlphaGo Thinks AI Is Taking the Wrong Path

Published

on

The Man Behind AlphaGo Thinks AI Is Taking the Wrong Path


David Silver gave the world its very first glimpse of superintelligence.

In 2016, an AI program he developed at Google DeepMind, AlphaGo, taught itself to play the famously difficult game of Go with a kind of mastery that went far beyond mimicry.

Silver has since founded his own company, Ineffable Intelligence, that aims to build more general forms of AI superintelligence. The company will do this, Silver says, by focusing on reinforcement learning, which involves AI models learning new capabilities through trial and error. The vision is to create “superlearners” that go beyond human intelligence in many domains.

This approach stands in contrast to how most AI companies plan to build superintelligence, by exploiting the coding and research capabilities of large-language models.

Silver, speaking to WIRED from his office in London, says he thinks this approach will fail. As amazing as LLMs are, they learn from human intelligence—rather than building their own.

“Human data is like a kind of fossil fuel that has provided an amazing shortcut,” Silver says. “You can think of systems that learn for themselves as a renewable fuel—something that can just learn and learn and learn forever, without limit,” he says.

I’ve met Silver a few times and—despite this proclamation—he’s always struck me as one of the more humble people in AI. Sometimes, when talking about ideas he considers silly, he flashes a puckish grin. Right now, though, he’s deadly serious.

“I think of our mission as making first contact with superintelligence,” he says. “By superintelligence I really mean something incredible. It should discover new forms of science or technology or government or economics for itself.”

Five years ago, such a mission might have seemed ridiculous. But tech CEOs now routinely talk about machines outpacing human intelligence and replacing entire categories of workers. The idea that some new technical twist might unlock superhuman AI capabilities has recently spawned a raft of billion-dollar startups.

Ineffable Intelligence has so far raised $1.1 billion in seed funding at a valuation of $5.1 billion—an enormous sum by European AI standards. Silver has also recruited top AI researchers from Google DeepMind and other frontier labs to join his endeavor.

Silver says he will give all of the money he makes from equity in Effable Intelligence—a sum that could amount to billions if he is successful—away to charity.

“It’s a huge responsibility to build a company focusing on superintelligence,” he tells me. “I think this is something that has to be done for the benefit of humanity, and any money that I make from Ineffable will will go to high-impact charities that save as many lives as possible.”

Total Focus

Silver met Demis Hassabis, the CEO of Google DeepMind, at a chess tournament when they were kids, and the pair later became lifelong friends and collaborators.

They remained close after Silver left Google DeepMind, which he did only because he wanted to chart a completely new path. “I feel it’s really important that there is an elite AI lab that actually focuses a hundred percent on this approach,” he says. “That it’s not just a corner of another place dedicated to LLMs.”

The limits of the LLM-based approach can be seen, Silver says, with a simple thought experiment. Imagine going back in time and releasing a large language model in a world that believed the world was flat. Without being able to interact with the real world, the system, he says, would remain an avid flat-earther, even if it continued to improve its own code.

An AI system that can learn about the world for itself, however, could make its own scientific discoveries.



Source link

Continue Reading

Tech

The Best iPhone Charger for Late-Night Doomscrolling

Published

on

The Best iPhone Charger for Late-Night Doomscrolling


The best iPhone charger depends on several factors. Are you topping off your battery on the go? Do you want to charge your iPhone as quickly as possible? Are you charging it overnight on your nightstand? The best gear recommendation is going to change with the situation. Luckily, the WIRED Reviews team tests iPhone chargers in the field all year long. There’s not a day that goes by that at least one of us is not assessing at least one iPhone charger. I’ve gathered up our favorite picks for every scenario.

Be sure to check out our related buying guides, like the Best Power Banks, the Best 3-in-1 Chargers, and the Best Wireless Chargers.

Table of Contents

The Best iPhone Chargers

Best Wall Charger for iPhone

Photograph: Julian Chokkattu

Anker

Nano 45W With USB-C Cable

This Anker charger is slick and has folding prongs so it’s easy to travel with, but the best part is that it can charge your phone at 40 watts (average is 20 to 27 watts). That means you can get up to 50 percent battery life in only 20 minutes. Not all iPhone models support charging this fast—it’s limited to iPhone 17, iPhone 17 Pro, and iPhone 17 Pro Max—but you may as well future-proof your gear if you’re shopping for a wall charger, even if your phone can’t take full advantage of those speeds yet.

Best Power Bank for iPhone

Small rounded rectangular bright blue device beside a black rectangular device, both with strap handles.

We do recommend the Anker Laptop Power Bank as our top-pick power bank, but if you’re only trying to top off your iPhone, this is a very reliable and neat-looking power bank. It’s svelte, smaller than a deck of cards, and can deliver 20 watts to two devices at once. Nimble also makes a slightly larger version, which has a larger capacity and can charge at up to 65 watts. Aside from the cool design featuring speckled colors and a lanyard loop, Nimble also uses bioplastics, recycled materials, and minimal packaging. A USB-C charger is included in the box.

Best MagSafe Portable Charger for iPhone

Gear-Anker_MagGo_Qi2-SOURCE-Simon-Hill

Anker

MagGo Power Bank (10K) (Qi2)

This 10,000-mAh power bank can charge your device at up to 15 watts, but it’ll also charge older devices at a slower rate. It has a built-in kickstand and an LED display that lets you know how much power is left at a glance. It works in portrait or landscape modes. Be aware that it won’t be able to charge most phones fully more than once, but it’s hard to beat if you’re seeking wireless charging on the go. If you want a bigger capacity or faster charging, you don’t want MagSafe.

Best 3-in-1 Charger for iPhone

Image may contain: Wood, Plywood, Electrical Device, Microphone, Furniture, Table, Hardwood, Tabletop, Person, and Desk

Belkin

3-in-1 Qi2 Charging Stand

The Belkin 3-in-1 can charge your compatible iPhone at 15 watts, plus your AirPods and your Apple Watch at the same time. The charging pad can be tilted to your preferred angle, including in landscape orientation if you want to watch a video or put your phone in StandBy mode. The USB-C cable is permanently attached, which you may or may not like. Check our best 3-in-1 chargers buying guide for additional picks.

Best 2-in-1 Charger for iPhone

Image may contain: Electronics, and Speaker

Photograph: Louryn Strampe

Mophie

2-in-1 Wireless Charging Stand

I love a 3-in-1 charger as much as the next tech nerd, but sometimes they’re overkill. My Apple Watch battery usually lasts all day long, but I can chew through my older AirPods battery before my lunch break hits, and my iPhone battery might be depleted too, depending on whether or not I’m streaming Max Velocity off to the side. This 2-in-1 charger has been my steadfast desktop companion. Mophie makes another version that tops off your Apple Watch and iPhone instead of your headphones, which might be what you want if you’re rocking wired headphones or you’re making intense use of a walking pad throughout the day. There’s a 40-watt wall charger in the box—a rarity these days!—plus a USB-C cable that winds neatly into the base. It’s easy to adjust the angle of your iPhone as well, and I’ve found the base very sturdy. If you want to charge, but not necessarily all of the possible devices simultaneously, these might be what you seek.

Anker

Prime USB-C to USB-C Cable

This braided nylon USB-C cable has a durable exterior made from recycled plastic. The cable is rugged, with Anker promising that it can operate in temperatures ranging from negative 40 degrees to 176 degrees Fahrenheit. It’s backed by a lifetime warranty. It’s got a built-in cable management loop. It’s more than enough cable for your iPhone. Read our guide to the Best USB-C Cables for more picks.

Ugreen

USB-C to Lightning Cable

If your iPhone is still rocking the Lightning cable, this is gonna be way better than whatever shoddy cable Apple sent you. It’s durable and is Made for iPhone-certified, so you won’t have any problems getting it to work. It comes in 3-, 6-, or 10-foot lengths with a two-year warranty. Best of all, the exterior casing will stay intact, unlike what you’d probably get with Apple’s cables.



Source link

Continue Reading

Trending