logo

AI in the Driver’s Seat: How the ‘Bissa’ Scanner Hijacked 900+ Firms in Weeks

ID: ee7faf8b-5ad9-5ed1-a2e9-52365e8918ce

STIX ID: report--ee7faf8b-5ad9-5ed1-a2e9-52365e8918ce

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Ddos

...
...

**Executive summary:** Researchers discovered an exposed command-and-control server revealing a large, AI-assisted exploitation campaign led by a single operator (“Dr.Tube”) that used the Bissa scanner to mass-exploit CVE-2025-55182 (React2Shell), compromising over 900 companies and automatically exfiltrating more than 30,000 distinct .env files and tens of thousands of credentials (notably Stripe, AWS, OpenAI, Google, Anthropic); the operation used AI tooling for exploit development and Telegram bots for real-time triage and alerting, with follow-on targeting focused on financial, cryptocurrency, and retail sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.