Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting
2026-04-22T20:51:59Z•9243bbf26ce3250f7a60b4ee4cb4eb7749ae167b46f53247a44faca527565091
CVE-2023-22527CVE-2023-46604Claude CodeOpenClawai-assistedakiraapache-activemqbissa-scannerbumblebeeconfluencecredential-harvestingexposed-servicesfog-ransomwareinitial-accessinterlock-ratlockbitlunar-spiderlynxmass-exploitationpassword-sprayransomhubransomwarercerdpseo-poisoning
What happened
Collection of DFIR Report posts describing active mass-exploitation and ransomware campaigns. Key findings include an exposed AI-assisted scanning/orchestration platform (“Bissa” using Claude Code and OpenClaw) used for large-scale credential harvesting and exploitation, an Apache ActiveMQ RCE exploitation (CVE-2023-46604) that led to LockBit ransomware, and an unpatched Confluence template injection exploit (CVE-2023-22527) used in ransomware intrusions. Additional reports cover multiple ransomware families and tooling (Lynx, Akira via Bumblebee, Lunar Spider, Interlock RAT, RansomHub, Fog),常
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- thedfirreport
- Record identifier
- 9243bbf26ce3250f7a60b4ee4cb4eb7749ae167b46f53247a44faca527565091
- Enrichment time
- 2026-04-22T20:51:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.