766 Next.js Hosts Breached via CVE-2025-55182 in 24 Hours — CVSS 10.0, Mass Credential Theft
The Hacker News·high signal
Cisco Talos uncovered 'UAT-10608,' a credential harvesting campaign exploiting CVE-2025-55182 (CVSS 10.0) in React Server Components and Next.js App Router that compromised 766 servers worldwide in 24 hours. Post-compromise, 91.5% of hosts leaked database credentials and 78.2% exposed SSH private keys, funneled to a C2 platform called 'NEXUS Listener.' Any builder running Next.js App Router should patch immediately — this is automated mass exploitation with a web GUI for the attackers.