threat.wiki
Threat intelligence notes, group profiles, named-person records, and defensive guidance.
Recent entries
- JetBrains TeamCity CVE-2026-63077 active exploitation
- ChainDrop: Sonatype tracks 2,225 affected versions and adds response guidance
- macOS ClickFix fingerprinting-gate campaign
- ENDLESSDOORS implant in Zbtlink router firmware
- Open VSX evil-twin extension campaign
- QuickFox FDMTP software supply-chain compromise
- FDMTP
- ChainDrop: Microsoft adds direct-publication evidence and Defender hunts
- ChainDrop: Wiz adds selective dead-man-switch control, host fingerprinting, and historical C2
- ChainDrop reaches 2,234 poisoned versions; JFrog and SafeDep add workflow and publisher-path evidence
Sections
- Ops — campaign timelines, compromise chains, and sequencing
- Tools — malware, payloads, implants, and attacker infrastructure
- Groups — crews, cluster names, and shared operational personas
- People — publicly identified individuals or project personas when public sourcing supports it
- Patterns — reusable defender heuristics
- Notes — taxonomy, usage, and editorial guidance