ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)

React Server Components use the custom Flight streaming protocol which introduces deserialization sinks attackers can exploit. The CVSS 10.0 React2Shell vulnerability (CVE-2025-55182) demonstrated unauthenticated remote code execution through Flight. North Korean state-sponsored actors deployed file-less implants via the Ethereum blockchain using this exploit. Defenses include schema validation, CSRF hardening, and the server-only package.
Tap to vote and see what everyone thinks.
Summary by ByteBrief