logo

Exposed Server Reveals AI-Assisted Credential Harvesting Factory

ID: 95c32520-e808-5143-8fad-1b86ce2742de

STIX ID: report--95c32520-e808-5143-8fad-1b86ce2742de

Feed Name: The Cyber Express

Threat Score
92/100

Date Published: 2026-04-22

Date Updated: 2026-04-23

Author: Mihir Bagwe

...
...

Executive summary: A DFIR investigation exposed a live criminal operation named “Bissa scanner” that weaponized CVE-2025-55182 (React2Shell, CVSS 10.0) to run internet-scale scanning and unauthenticated RCE, leading to at least ~900 confirmed compromises and a repository of 13,000+ files containing harvested .env secrets and high-value credentials across AI providers, cloud platforms, payment services, databases, and identity systems; the operation used AI assistants (Claude Code, OpenClaw) to refine the pipeline and Telegram bots for real-time triage and alerting — the report urges immediate patching, secret rotation, metadata access restrictions, and CI/CD secrets scanning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.