Hackers Use Telegram Bots to Track 900+ Successful React2Shell Exploits
ID: 8fb5efbc-a17e-5a9d-a820-6b948a365a51
STIX ID: report--8fb5efbc-a17e-5a9d-a820-6b948a365a51
Feed Name: cybersecurityNews.com
A mass exploitation campaign leveraging a critical Next.js vulnerability (CVE-2025-55182, "React2Shell") used an automated scanner called Bissa to pull .env files and sensitive credentials from internet-facing web apps; the operator automated real-time alerts via Telegram bots (@bissapwned_bot and @bissa_scan_bot) and staged harvested data in cloud storage (bissapromax), impacting hundreds of organizations and collecting tens of thousands of secrets including cloud and payment keys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
