[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDf4Bb8MYUq_QUTaJjVba7MNZVpjudylhY7DMDnRBvT8":3},{"article":4,"iocs":47,"watch_terms":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":31},"7de5884b-2571-49fc-8ffb-8328eed1b89c","Automated Credential Harvesting Campaign Exploits React2Shell Flaw","automated-credential-harvesting-campaign-exploits-react2shell-flaw","An emerging threat cluster tracked as UAT-10608 is exploiting vulnerable Web-exposed Next.js apps and using an automated tool to exfiltrate credentials, secrets, and other system data.","A threat cluster designated UAT-10608 is actively exploiting a vulnerability in Next.js applications exposed to the web, leveraging the React2Shell flaw to deploy automated credential harvesting tools. The campaign systematically exfiltrates credentials, secrets, and sensitive system data from compromised instances.","UAT-10608 exploits React2Shell flaw in Next.js apps for automated credential theft.",null,"https:\u002F\u002Fwww.darkreading.com\u002Fcyberattacks-data-breaches\u002Fautomated-credential-harvesting-campaign-react2shell","https:\u002F\u002Feu-images.contentstack.com\u002Fv3\u002Fassets\u002Fblt6d90778a997de1cd\u002Fbltd8e96d3db38c0b12\u002F69d39a16d1f628212adfd236\u002Fmaliciouscode_Victor_Koldunov_Alamy.png?width=1280&auto=webp&quality=80&disable=upscale","2026-04-06T15:31:09+00:00","2026-04-06T16:00:13.925405+00:00",8,[18,21,24],{"name":19,"type":20},"UAT-10608","threat_actor",{"name":22,"type":23},"Next.js","product",{"name":25,"type":26},"React2Shell","technology","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":27,"icon":11,"name":29,"slug":30},"Vulnerabilities","vulnerabilities",[32,37,42],{"category":33},{"id":34,"icon":11,"name":35,"slug":36},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":38},{"id":39,"icon":11,"name":40,"slug":41},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":43},{"id":44,"icon":11,"name":45,"slug":46},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[48],{"type":41,"value":25,"context":49},"Vulnerability exploited by UAT-10608 for credential harvesting in Next.js applications",[22]]