China-Linked Actors Exploit New Vulnerabilities Within Hours of Disclosure
China-affiliated threat actors, including Vault Panda and Genesis Panda, are exploiting critical vulnerabilities like React2Shell within 24 hours of their public disclosure, highlighting a shrinking window for defenders.

China-linked threat actors are demonstrating an alarming speed in weaponizing newly disclosed critical vulnerabilities, with some groups exploiting flaws within a mere 24 hours of public release. CrowdStrike's latest findings reveal that sophisticated China-nexus groups, specifically Vault Panda (UNC6588) and Genesis Panda (REF0657, Earth Lamia), were observed conducting rapid, systematic attacks targeting the React2Shell exploit.
React2Shell is a critical web application vulnerability that permits unauthenticated remote code execution in React Server Components and Next.js applications. The vulnerability was initially disclosed in December 2025, with patches released concurrently. Despite the availability of fixes, these threat actors moved with exceptional swiftness, deploying a variety of malicious tools, including remote access trojans (RATs), against their targets to conduct post-exploit activities such as credential harvesting.
"The speed of this response highlights their posture as adversaries who actively monitor vulnerability disclosures, rapidly validate exploitability, and pre-stage tooling in anticipation of a constantly changing attack surface," researchers noted in the CrowdStrike 2026 Threat Hunting Report. This rapid exploitation trend is not isolated to React2Shell; CrowdStrike observed that in 88% of all publicly disclosed vulnerability exploits in the first half of 2026, intrusion occurred within 48 hours of the vulnerability's release.
Furthermore, the report indicates a concerning 42% year-over-year increase in zero-day exploitation from 2024 to 2025. This acceleration in exploitation timelines is occurring even before the full integration of frontier artificial intelligence (AI) into vulnerability research. Researchers anticipate a further compression of the disclosure-to-exploitation window in the coming months, especially with the advent of AI tools designed to discover and fix vulnerabilities at scale, such as Anthropic’s Mythos and OpenAI’s GPT-5.4-Cyber and GPT-5.5-Cyber.
"Frontier models are likely contributing to the rising volume of disclosed vulnerabilities, exacerbating the challenges faced by network defenders as they attempt to cope with ever-shrinking patch windows," the researchers added. This escalating threat landscape underscores the critical need for organizations to adopt proactive security measures and accelerate their patch management processes.
The CrowdStrike report also sheds light on a dramatic rise in identity-based attacks, many of which are linked to the increasing use of AI. A growing trend involves threat actors attempting to compromise victims' own AI platforms through techniques like LLMJacking. This involves adversaries seeking access to corporate LLM API credentials to sabotage AI services beyond their normal operating capacity, aiming to inflict financial harm.
In one documented campaign, a threat actor sent nearly 200,000 API requests within a two-minute period after gaining elevated access to a cloud computing service offering access to foundation models. Additionally, CrowdStrike detected a doubling in the number of intrusions where vishing (voice phishing) was used as the initial access vector in H1 2026 compared to H1 2025. AI tools, including deepfakes, are enhancing these vishing attacks, making them more convincing and harder for defenders to detect.
The report concludes that vishing has emerged as a key technique for e-crime actors due to its low detectability and the scarcity of malicious activity markers available for defenders. The combination of rapid vulnerability exploitation, AI-driven attack enhancements, and sophisticated identity-based attacks presents a formidable and evolving challenge for cybersecurity professionals worldwide.