AI in the Driver’s Seat: How the ‘Bissa’ Scanner Hijacked 900+ Firms in Weeks
ID: ee7faf8b-5ad9-5ed1-a2e9-52365e8918ce
STIX ID: report--ee7faf8b-5ad9-5ed1-a2e9-52365e8918ce
Feed Name: securityonline.info
**Executive summary:** Researchers discovered an exposed command-and-control server revealing a large, AI-assisted exploitation campaign led by a single operator (“Dr.Tube”) that used the Bissa scanner to mass-exploit CVE-2025-55182 (React2Shell), compromising over 900 companies and automatically exfiltrating more than 30,000 distinct .env files and tens of thousands of credentials (notably Stripe, AWS, OpenAI, Google, Anthropic); the operation used AI tooling for exploit development and Telegram bots for real-time triage and alerting, with follow-on targeting focused on financial, cryptocurrency, and retail sectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
