Blog

Explore our latest articles on platform security, cloud vulnerabilities, and industry best practices. Our team shares research findings, technical tutorials, and security insights to help you stay informed.

terminal

$ subscribe_to_updates

Subscribe to access private blog posts, early vulnerability disclosures, and security insights not available to the public.

# Filter by Topic

React2Shell for Lambdas

By Matthew Keeley | January 26, 2026

Existing scanners miss CVE-2025-55182 in serverless Lambda deployments. While traditional RCE is blocked by Webpack bundling, the vulnerability enables Server Side JavaScript Injection (SSJI) that can exfiltrate AWS credentials, often more dangerous than shell access in cloud environments.

Learn more