CVE
CVE-2025-11953
- First Reported
- May 21, 2026
- Latest Reported
- May 21, 2026
Reported Context (1)
- (Turkey), linked to a Cloud Storage impersonation phishing campaign.Active exploitation of CVE-2025-11953 (Metro4Shell) in React Native CLI was observed with source IP 5.109.182[.]231 on Saudi Arabia's Hunt.io Report Maps 1,357 C2 Servers Across 98 Middle Eastern Providers
Malware (17)
Threat Actors (8)
MITRE ATT&CK (9)
Vendors (21)
Products (8)
Tools (8)
Industries (5)
Countries (16)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.