Infosecurity

China-Linked Hackers Weaponize New Flaws in Under a Day, CrowdStrike Warns

Published

on

The 24-Hour Window Just Got Smaller

It used to be that defenders had a few days, maybe a week, to patch a newly disclosed vulnerability before attackers caught on. Those days are gone. CrowdStrike has documented China-linked threat actors weaponizing a critical flaw in less than 24 hours from public disclosure.

The groups in question — Vault Panda and Genesis Panda — moved with alarming speed against the React2Shell vulnerability. That’s the critical web application bug allowing unauthenticated remote code execution in React Server Components and Next.js applications. It was disclosed in December 2025, with patches released at the same time.

This isn’t a theoretical concern. These are active campaigns.

Who Are Vault Panda and Genesis Panda?

Both are China-nexus groups tracked by CrowdStrike. Vault Panda (UNC6588) and Genesis Panda (REF0657, Earth Lamia) were observed deploying remote access trojans (RATs) and harvesting credentials shortly after the React2Shell disclosure.

They didn’t just scan for the flaw. They came prepared with tooling, ready to deploy at a moment’s notice. CrowdStrike researchers described the behavior in the CrowdStrike 2026 Threat Hunting Report, published August 3.

The report states: “The speed of this response highlights their posture as adversaries who actively monitor vulnerability disclosures, rapidly validate exploitability, and pre-stage tooling in anticipation of a constantly changing attack surface.”

AI Is Compressing Patch Windows Further

React2Shell isn’t an isolated case. CrowdStrike found that in 88% of publicly disclosed vulnerability exploits during H1 2026, the intrusion occurred within 48 hours of release. That’s a staggering figure.

Zero-day exploitation also jumped 42% year-over-year from 2024 to 2025. And here’s the worrying part: these trends predate the integration of frontier AI into vulnerability research.

AI tools like Anthropic‘s Mythos and OpenAI‘s GPT-5.4-Cyber and GPT-5.5-Cyber are designed to find and fix vulnerabilities at scale. But they’re also giving attackers a head start.

CrowdStrike researchers warn: “Frontier models are likely contributing to the rising volume of disclosed vulnerabilities, exacerbating the challenges faced by network defenders as they attempt to cope with ever-shrinking patch windows.”

Translation: expect the timeline between disclosure and exploitation to compress even further in the coming months.

Identity Attacks: The New Frontline

The report also shines a light on identity-based attacks, which are rising dramatically. A big driver? AI.

LLMJacking: When Attackers Hijack Your AI

One notable trend is LLMJacking. Financially motivated adversaries compromise a victim’s corporate LLM API access, then run up massive bills or sabotage the AI services beyond normal capacity. The goal is financial harm.

In one campaign, a threat actor sent nearly 200,000 API requests in just two minutes after gaining elevated access to a cloud computing service offering foundation models. Two minutes. That’s not a typo.

Vishing Doubles as Initial Access Vector

CrowdStrike also detected a doubling in intrusions using vishing as the initial access vector in H1 2026 compared to H1 2025. Vishing — voice phishing — involves impersonating individuals over phone calls to bypass authentication.

AI has supercharged this technique. Deepfakes make it easier to sound like a CEO or IT admin. And because vishing leaves few digital markers, it’s hard for defenders to detect.

The report notes vishing has become a key technique for e-crime actors precisely because detection is so difficult.

What This Means for Defenders

The takeaway is sobering. Patch windows are shrinking. Attackers are using AI to move faster, and identity-based attacks are becoming harder to spot.

For security teams, this means a few things:

  • Prioritize patching based on exploitability, not just severity scores.
  • Assume your AI services will be targeted — monitor API usage for anomalies.
  • Train employees to question phone calls, even from familiar voices.
  • Invest in detection tools that can spot post-exploit activity quickly.

The gap between disclosure and exploitation is closing. The question is whether defenders can keep up.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version