Robin’s Newsletter #390

7 December 2025. Volume 8, Issue 49
Critical vuln in React. 'Performative' action taken against scam compound in Myanmar. No E2EE for smart toilet camera.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

This week

Need to Know, 7th December 2025

  • Critical ‘React2shell’ vuln in common web app software
  • Second Cloudflare outage in as many months
  • Questions remain over extent of Mixpanel breach
  • US, UK lawmakers grapple with deterrence policies
  • Myanmar scam compound actions ‘performative’

Interesting stats

20 years old is the age of ‘peak cyber criminality’, after which people tend to grow out of it, according to a new study by the Dutch government, with only  4% of those who embark on an early criminal career have a high likelihood of continuing with criminal behaviour after this age. This ‘peak’ is similar for other types of crime, too. LINK

Five things

  1. React2shell: A ‘perfect 10’ vulnerability in React has been discovered and exploit code released. CVE-2025-55182 affects part of the React Server Components in versions 19.0.1, 19.1.2, and 19.2.1 and does not require any authentication to exploit. Researchers at cloud security vendor Wiz say they have had “a near 100% success rate,” and that this “can be leverage[d] to… full remote code execution”. Other downstream packages, such as Next.js, make it difficult to ascertain the scale of the potential issue. Scanning activity for the vulnerability has been extensive. Security researchers may account for a larger share of this traffic; however, Palo Alto’s Unit 42 says it has seen around 30 organisations compromised using a vulnerability it believes is linked to a Chinese initial access broker. CISA has added the bug to its ‘known exploited vulnerabilities’ KEV list, and teams using React Server Components should follow the advice to upgrade as a priority. REACT2SHELL, SCANNING, ADVISORY

  2. Cloudflare suffered a second outage in as many months, trying to respond to the React2shell vulnerability (above). Just over a quarter of Cloudflare’s web traffic was affected by the incident. “The issue was not caused, directly or indirectly, by a cyber attack on Cloudflare’s systems or malicious activity of any kind”, a blog post from CTO Dane Knecht says. Instead, the outage occurred when an update was pushed to the firm’s web application firewall to detect and prevent abuse of the vulnerability. Customers on the ‘older’ FL1 proxy solution, which also had the Cloudflare Managed Ruleset deployed, were impacted. Around 30 minutes after starting, Cloudflare has restored service. There’s a good write-up on Knecht’s blog, which highlights how complicated systems can be and that, even with safeguards built in, there are plenty of edge cases. CLOUDFLARE, WRITE-UP

  3. Mixpanel has been notably quiet on the extent of a breach they announced just before the US Thanksgiving holiday. Information was more forthcoming from OpenAI, which, until this incident, was a customer; however, Mixpanel’s CEO, Jen Taylor, has been avoiding questions from journalists like TechCrunch’s Zack Whittaker. Mixpanel is a web and mobile app analytics company. Their solution monitors how users interact — where and what they click, how long actions take, and, in some cases, full replays of sessions — and so understanding the extent of the breach and what information may have been stolen is important. Taylor’s blog post announcing the incident says that Mixpanel “proactively communicated with all impacted customers.” MIXPANEL

  4. Effective deterrence? US Lawmakers have introduced The Cyber Deterrence and Response Act, legislation that would formally designate ‘critical cyber threat’ [actors], create an attribution framework, and impose ‘robust sanctions’ against designated actors. The US already attributes actors and imposes sanctions against threat actors: we’ll see over time whether this becomes more substantive, aligns with existing practices, or is just performative. Sticking with deterrence, in the UK, ministers are exploring exempting the NHS from a ban on paying ransoms to cybercriminals. Security minister Dan Jarvis said they were looking “very carefully at national security exemptions”. I think carving out exceptions only paints a larger target on the healthcare, water, or telecoms businesses that would be in scope: I think “we know you have an exception and need to get service restored” would become an opening line from cybercriminals. Better to work out if/how you make the ban work for all CNI than try and tier it. DETERRENCE, RANSOM BAN

  5. Scam centres: The US DOJ has seized a website impersonating a foreign exchange and commodities trading platform used by scammers to steal money from victims. The fake apps allowed victims to deposit funds, and then showed their returns increasing. Of course, there was never any way to cash out. Authorities in Thailand announced that they had seized assets worth more than $300 million and issued arrest warrants for 42 people in a crackdown on scammers, including Chinese-Cambodian self-styled ‘entrepreneur and philanthropist’ Chen Zhi, who heads the Prince Group, and is the subject of recent US sanctions. It’s good to see this traction: recent photos released by Myanmar’s military showing the destruction of parts of the KK Park scam compound are widely thought to have been “performative”. At the same time, officials say “a total of 237 buildings out of 635 illegal buildings have so far been demolished”. It’s easy to think of scammers as hapless, two-bit operations preying on vulnerable people, but KK Park is massive (see satellite photo below). These are well-resourced, organised criminal operations operating on a massive scale. And ‘revenues’ earned from cyber scams in Myanmar, Cambodia, and Laos represent anywhere from 23% to 68% of those countries’ GDP. They are the de facto economy. Taking action will require political will and international support. DOJ, THAILAND, KK PARK, GDP

KK Park after recent building demolitions (source: Wired / Vantor)

A significant portion of the gross domestic product of Myanmar, Cambodia, and Laos is estimated to come from cyber scams (source: The Guardian)

In brief

  • ⚠️ Incidents: South Korea’s ‘Amazon’, e-commerce business Coupang has suffered a breach and confirmed that 33.7 million customer accounts have been compromised (or ~65% of the country). The Royal Borough of Kensington and Chelsea says that “some data has been copied and then taken away” during an incident last week. Twins Muneeb and Sohaib Akhter face charges for deleting around 96 databases holding US federal government data after they were fired. The insider incident occurred earlier this year, and some of the ChatGPT questions asked to help cover their tracks are hilarious. However, the pair are no strangers to this sort of antics, having pleaded guilty to cybercrimes in 2015, including breaking into State Department systems. You’d think that kind of thing would crop up on background checks. COUPANG, RBKC, INSIDER

  • 🕵️ Threat Intel: Over 140 Chrome and Edge browser extensions with over 4.3 million installs have been taken over to run malware in a campaign Koi Security dubs “ShadyPanda”. Some of the browser extensions were originally submitted in 2018, with malicious activity appearing to commence in 2023. Capabilities include a backdoor, session and cookie access, reporting on search queries, keystrokes, and mouse clicks, and ad fraud. Push Security says Google and Facebook ad manager accounts are being targeted in a phishing campaign that uses Calendly lures from popular brands. CISA is warning VMware vSphere operators that Chinese-aligned groups are targeting their servers with Brickstorm malware. Where attackers gain access, they create hidden virtual machines that they control and use to steal snapshots of other, legitimate virtual machines to aid credential theft. EXTENSIONS, AD MANAGER, BRICKSTORM

  • 🛠️ Security engineering: A third wave of Glassworm infected VS Code packages is doing the rounds on both the OpenVSX and Microsoft Visual Studio Marketplace. Around 400,000 secrets were exposed after hundreds of NPM packages were infected with the Shai-Hulud worm last week. Almost two-thirds of infections were through the @postman/[email protected] and @asyncapi/[email protected] packages. Software supply chains are complex, and not everyone has a good handle on their CI/CD tooling and build pipelines: often, they’ve been set up for speed and flexibility rather than security. I suspect this won’t be the last we hear of Shai-Hulud. GLASSWORM, SHAI-HULUD

  • 🧿 Privacy: The UK Home Office is seeking to deploy facial recognition technology on a “significantly greater scale” to aid law enforcement. A consultation has been launched that will run through 12th February. A report from the National Physical Laboratory has found that policy facial recognition tech is “more likely to incorrectly include some demographic groups” in its searches, a key concern of civil liberties groups. Around two-thirds of the UK public are in favour of this as long as ‘appropriate protections’ are in place. And that’s the rub: many of those will not have any idea what the protections should be. Tools like this can undoubtedly be extremely helpful; however, claims that it is “generally less intrusive [than collecting DNA]” are not really the point and aren’t exactly reassuring. FACIAL RECOGNITION

  • 👮 Law Enforcement: The Supreme Court is to hear the case between American ISP Cox Communications and Sony. The case centres on users pirating music and, in the record labels’ eyes, the ISP failing to do enough to combat this illegal activity. PIRACY

  • 🗞️ Industry news: NATO conducted its largest ever cyber defence exercise this week, with over 1,300 participants from 29 countries. NATO

And finally

  • Oh crap: ‘end-to-end encrypted’ (checks notes) smart toilet cameras from Kohler are not, in fact, end-to-end encrypted. The device transmits data using TLS encryption (much the same as when requesting a website), but it’s decrypted upon reaching Kohler’s servers for processing, which may include training AI. The product marketing team put their foot in it with this one. The $599 smart thing will advise on gut health and hydration, and even includes a fingerprint reader to track who is using the toilet. OK then. KOHLER
Robin

  Robin's Newsletter - Volume 8

  React React2shell Cloudflare Mixpanel Deterrence Cyber Deterrence and Response Act 2025 Ransomware Myanmar KK Park Scammers Cybercrime Glassworm Shai-Hulud Insider threat Facial Recognition