China's Cyber Siege: Brickstorm, Warp Panda, and React2Shell Ravage US Infrastructure episode artwork

EPISODE · Dec 7, 2025 · 7 MIN

China's Cyber Siege: Brickstorm, Warp Panda, and React2Shell Ravage US Infrastructure

from Red Alert: China's Daily Cyber Moves · host Inception Point AI

This is your Red Alert: China's Daily Cyber Moves podcast. I’m Ting, and listeners, we’re going straight to battle stations. In the last 96 hours, the big red blinking light is a perfect storm of Chinese state-backed activity: Brickstorm inside US infrastructure, Warp Panda prowling VMware, and Chinese APTs pile‑driving the new React2Shell bug that just detonated across the JavaScript world. Timeline first, because I know you’re all running incident response playbooks in your heads. December 3: according to coverage of AWS threat intel and the AWS Security Blog, Chinese state‑nexus groups like Earth Lamia, Jackpot Panda, and UNC5174 start hammering the React2Shell vulnerability, CVE‑2025‑55182, within hours of disclosure. Tenable Research calls it a CVSS 10.0 remote code execution flaw in React Server Components, with over 77,000 internet‑exposed IPs vulnerable and about 23,700 of those in the United States. Palo Alto Networks reports more than 30 organizations already compromised, with Cobalt Strike, Snowlight, and Vshell lighting up victim networks. December 4: Google Threat Intelligence and CyberScoop‑covered briefings reveal a grim picture of long‑term Chinese espionage: Brickstorm malware quietly sitting inside US critical infrastructure and government networks since at least 2022, with an average dwell time of 393 days. CISA’s Nick Andersen says state actors are embedding “to enable long‑term access, disruption, and potential sabotage.” Austin Larsen from Google explains Brickstorm targets VMware vSphere and Windows, reinfects if removed, and tunnels laterally like it owns your data center. December 5: CISA, NSA, and the Canadian Centre for Cyber Security drop a joint advisory on Brickstorm, warning critical infrastructure operators that Chinese state‑sponsored actors are backdooring VMware vCenter and vSphere, often via a China‑linked group CrowdStrike tracks as Warp Panda. Homeland Security Today reports that dozens of US organizations are already affected, plus downstream victims that never saw the initial breach. Same day, CISA adds React2Shell to the Known Exploited Vulnerabilities catalog and orders US federal agencies to patch by December 26. Cloudflare rushes out an emergency WAF rule; BleepingComputer and others report the mitigation misfire briefly knocks out around a quarter of their HTTP traffic, reminding everyone that one bug plus one config push can ripple across half the internet. December 6–7: Shadowserver and GreyNoise see live exploitation traffic surge, including from Chinese infrastructure. Data Breaches Digest and security blogs flag React2Shell and Brickstorm together as the new “daily drivers” for China‑nexus operators going after government, healthcare, legal, manufacturing, and cloud‑heavy tech. So what does this mean, right now, for listeners defending US networks? If you run React, Next.js, or anything with React Server Components exposed to the internet, your priority zero is to patch CVE‑2025‑55182, ve This content was created in partnership and with the help of Artificial Intelligence AI.

Episode metadata supplied by the publisher feed · Published Dec 7, 2025

Embed this episode

NOW PLAYING

China's Cyber Siege: Brickstorm, Warp Panda, and React2Shell Ravage US Infrastructure

0:00 7:52

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Red Alert: China's Daily Cyber Moves?

This episode is 7 minutes long.

When was this Red Alert: China's Daily Cyber Moves episode published?

This episode was published on December 7, 2025.

Can I download this Red Alert: China's Daily Cyber Moves episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!