#BissaScanner
March-April 2026 saw commercial AI, including Claude Code, used in real attacks for espionage, phishing-as-a-service, and exploit research. Attackers abused config files and stolen AI creds, shrinking patch windows. #Mexico #ClaudeCode #EvilTokens
AI Threat Landscape Digest March-April 2026
During March–April 2026, commercial AI models like Claude Code moved into real offensive use across criminal campaigns, espionage, phishing-as-a-service, and vulnerability research. The article highlights how attackers weaponized persistent configuration files, harvested AI provider credentials, and compressed the patch window for newly disclosed flaws. #ClaudeCode #GTG-1002 #BissaScanner #EvilTokens #CVE-2025-55182 #CVE-2025-59536 #CVE-2026-21852 #CVE-2026-34197 #CVE-2026-33626
www.hendryadrian.com
May 27, 2026 at 1:30 AM
An exposed server reveals AI-driven mass exploitation using Bissa Scanner and React2Shell (CVE-2025-55182), confirming 900+ breaches and harvesting thousands of credentials with Claude Code and Telegram bots. #BissaScanner #AIExploitation
Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting
We discovered an exposed server that revealed a large-scale, AI-assisted exploitation and credential-harvesting operation built around the Bissa scanner and leveraging React2Shell (CVE-2025-55182) to scan millions of targets and confirm 900+ compromises. The operator used Claude Code and OpenClaw for workflow orchestration, Telegram bots for alerting, and S3-compatible Filebase buckets (bissapromax) to aggregate tens of thousands of harvested .env files and credentials. #React2Shell #BissaScanner
www.hendryadrian.com
April 23, 2026 at 8:15 AM