Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting

2026-04-22T20:51:59Z9243bbf26ce3250f7a60b4ee4cb4eb7749ae167b46f53247a44faca527565091
CVE-2023-22527CVE-2023-46604Claude CodeOpenClawai-assistedakiraapache-activemqbissa-scannerbumblebeeconfluencecredential-harvestingexposed-servicesfog-ransomwareinitial-accessinterlock-ratlockbitlunar-spiderlynxmass-exploitationpassword-sprayransomhubransomwarercerdpseo-poisoning

What happened

Collection of DFIR Report posts describing active mass-exploitation and ransomware campaigns. Key findings include an exposed AI-assisted scanning/orchestration platform (“Bissa” using Claude Code and OpenClaw) used for large-scale credential harvesting and exploitation, an Apache ActiveMQ RCE exploitation (CVE-2023-46604) that led to LockBit ransomware, and an unpatched Confluence template injection exploit (CVE-2023-22527) used in ransomware intrusions. Additional reports cover multiple ransomware families and tooling (Lynx, Akira via Bumblebee, Lunar Spider, Interlock RAT, RansomHub, Fog),常

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
thedfirreport
Record identifier
9243bbf26ce3250f7a60b4ee4cb4eb7749ae167b46f53247a44faca527565091
Enrichment time
2026-04-22T20:51:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.