[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fgw5XUrFqijF2kfF9IjN8oRKFtv_hmdf1quTbjj1HoxQ":3},{"article":4,"iocs":41,"watch_terms":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":25},"65e08310-835d-4de4-8562-4cc9af46249f","We identified an exposed server that provided unusual visibility into a large-scale, multi-victim...","we-identified-an-exposed-server-that-provided-unusual-visibility-into-a-large-sc-43da67","We identified an exposed server that provided unusual visibility into a large-scale, multi-victim exploitation and collection operation. Artifacts on the host showed that Claude Code and OpenClaw were embedded in the operator's day-to-day workflow, supporting troubleshooting, https:\u002F\u002Ft.co\u002Fis2hE1e2Yd","Security researchers discovered an exposed server belonging to threat actors conducting a widespread multi-victim exploitation and collection campaign. Artifacts on the host indicated the operators were using Claude Code and OpenClaw tools as part of their operational workflow for troubleshooting and attack activities.","Exposed server reveals large-scale multi-victim exploitation operation using Claude Code and OpenClaw.",null,"https:\u002F\u002Fx.com\u002FTheDFIRReport\u002Fstatus\u002F2046966648444264638","https:\u002F\u002Fpbs.twimg.com\u002Fmedia\u002FHGhJUbwXAAAFxwZ.jpg","2026-04-22T14:57:34+00:00","2026-04-22T15:00:13.321768+00:00",7,[18],{"name":19,"type":20},"Claude Code","technology","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":21,"icon":11,"name":23,"slug":24},"Threat Intelligence","threat-intelligence",[26,31,36],{"category":27},{"id":28,"icon":11,"name":29,"slug":30},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":32},{"id":33,"icon":11,"name":34,"slug":35},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":37},{"id":38,"icon":11,"name":39,"slug":40},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",[42,45],{"type":40,"value":43,"context":44},"OpenClaw","Tool embedded in threat actor's operational workflow for exploitation activities",{"type":40,"value":19,"context":46},"AI tool integrated into threat actor's day-to-day operational workflow",[]]