LIVE NEWS
  • Trump dangles $500 ACA refund checks, but legal basis is unclear
  • Guest post: How extreme heat is ‘creeping’ from summer into autumn and spring
  • Musk threatens to sue filmmaker Alex Gibney for defamation : NPR
  • 25 Years After 9/11, What Makes a Good Counterterrorism Strategy?
  • Twenty-five years after 9/11, strategic shocks mustn’t cloud strategic thinking
  • Infectious diseases will seed new ground as the planet warms — here’s where they’ll spread
  • India crypto takedowns target 15 platforms
  • NFL’s Rams and 49ers head to Australia in international expansion
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Chinese Threat Actors Weaponize New Vulnerabilities in Under a Day
Cybersecurity

Chinese Threat Actors Weaponize New Vulnerabilities in Under a Day

primereportsBy primereportsAugust 3, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Chinese Threat Actors Weaponize New Vulnerabilities in Under a Day
Share
Facebook Twitter LinkedIn Pinterest Email


China-affiliated threat actors are capable of exploiting critical vulnerabilities within 24 hours of public disclosure, according to new findings from CrowdStrike.

The China-nexus groups Vault Panda and Genesis Panda were observed conducting rapid, systematic attacks that targeted the React2Shell exploit – a critical web application vulnerability that enables unauthenticated remote code execution in React Server Components and Next.js applications.

The flaw was disclosed in December 2025, with patches released in concurrence.

While multiple threat actors leveraged React2Shell in the wild, Vault Panda (UNC6588) and Genesis Panda (REF0657, Earth Lamia) were particularly fast in deploying various malicious tools against victims, including remote access trojans (RATs). These were used to conduct a range of post-exploit activities such as harvesting credentials.

“The speed of this response highlights their posture as adversaries who actively monitor vulnerability disclosures, rapidly validate exploitability, and pre-stage tooling in anticipation of a constantly changing attack surface,” the researchers noted in the CrowdStrike 2026 Threat Hunting Report, published on August 3.

AI Speeds up Vulnerability Exploitation

Overall, CrowdStrike observed that in 88% of publicly disclosed vulnerability exploits in H1 2026 the intrusion occurred within 48 hours of release. The firm also recorded a 42% year-over-year increase in zero day exploitation from 2024 to 2025.

The researchers noted that these patterns predate the integration of frontier AI into vulnerability research, therefore further compression of the timeline between disclosure and active exploitation should be expected in the coming months.

This follows the launch of AI tools like Anthropic’s Mythos and OpenAI’s GPT-5.4-Cyber and GPT-5.5-Cyber which have been designed to find and fix cybersecurity vulnerabilities at scale.

“Frontier models are likely contributing to the rising volume of disclosed vulnerabilities, exacerbating the challenges faced by network defenders as they attempt to cope with ever-shrinking patch windows,” the researchers added.

Identity Attacks Continue to Rise

The CrowdStrike report also highlighted a dramatic rise in identity-based attacks, largely linked to the use of AI.

This includes a growing trend of threat actors seeking to compromise victims’ own AI platforms via LLMJacking. This is at technique where financially motivated adversaries seek to obtain access to victims’ corporate LLM API access and sabotage the victim’s AI services beyond normal operating capacity to cause financial harm.

In one campaign, a threat actor sent nearly 200,000 API requests during a two-minute period after gaining elevated access to a cloud computing service offering access to foundation models.

CrowdStrike also detected a doubling in the number of intrusions involving vishing as the initial access vector in H1 2026 compared to H1 2025.

Vishing involves the impersonation of individuals via phone calls to bypass authentication requirements. These attacks have been enhanced by the use of AI tools, such as deepfakes.

The report noted that vishing has emerged as a key technique for e-crime actors as detection is difficult, with few markers of malicious activity available for defenders.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleTrump Media Is Now Selling Faster Access to Some Truth Social Posts
Next Article BlockDAG’s path to 3000x profits crushes Ondo and Pi predictions 
primereports
  • Website

Related Posts

Cybersecurity

Microsoft says September updates fix mouse settings reset issues

September 10, 2026
Cybersecurity

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

September 9, 2026
Cybersecurity

Microsoft Plugs Nearly 1,000 Security Holes – Krebs on Security

September 9, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Threat of further violence looms after Mexican cartel rampage

February 25, 2026116 Views

‘Two-sided risk’ Medicare Advantage plans improve patient outcomes

February 24, 202673 Views

An $18bn settlement – and Zuckerberg barely blinked. The tech titans must be stripped of their power, and soon | Jonathan Freedland

August 28, 202626 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Crypto
  • Cybersecurity
  • Geopolitics
  • Artificial Intelligence
  • Popular Now
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Trump dangles $500 ACA refund checks, but legal basis is unclear
  • Guest post: How extreme heat is ‘creeping’ from summer into autumn and spring
  • Musk threatens to sue filmmaker Alex Gibney for defamation : NPR
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.