External Publication
Visit Post

Hackers Exploit React2Shell to Hijack Web Traffic via Compromised NGINX Servers

The Hacker News | #1 Trusted Source for Cybersecurity News [Uno… February 5, 2026
Source
Cybersecurity researchers have disclosed details of an active web traffic hijacking campaign that has targeted NGINX installations and management panels like Baota (BT) in an attempt to route it through the attacker's infrastructure. Datadog Security Labs said it observed threat actors associated with the recent React2Shell (CVE-2025-55182, CVSS score: 10.0) exploitation using malicious NGINX

Discussion in the ATmosphere

Loading comments...