How Russian companies were hacked and by what means. Jet CSIRT study

General News

Summary

This article examines how Russian companies were breached and summarizes Jet CSIRT’s findings from the 2023–2025 period. It highlights common attack methods such as DDoS, phishing, exploitation of public-facing applications, and post-compromise activity. The piece also calls out a critical React Server Components vulnerability, CVE-2025-55182, known as React2Shell, and gives log-search and detection guidance. It includes practical indicators and auditd-based rules that security teams can use to detect suspicious shell execution on Linux web servers.

Classifications

industries
No industries detected
applications
ERP & Process Management

AskAI Classifications

Labels
Information Technology Software Development Cybersecurity

Linked Companies