RondoDox botnet exploited React2Shell to compromise IoT devices and Next.js servers over a nine-month global campaign.
December 2025, the RondoDox botnet operators have been targeting Next.js servers impacted by the React2Shell vulnerability.