threat.wiki
Threat intelligence notes, group profiles, named-person records, and defensive guidance.
Recent entries
- Oracle WebLogic Proxy Plug-in improper access control in CISA KEV (CVE-2026-21962)
- Benchmaxxing: when a benchmark becomes the target
- Shattering the Dream: Lazarus "Operation Dream Job" job-offer zero-day campaign
- workerd / Cloudflare Code Mode: sandbox escape and cross-tenant heap swipe
- CISA KEV August 11 additions: Windows WinSock zero-day, Metabase, and Cisco ASA/FTD
- StepSecurity annual census: 56 open source supply chain attacks (Aug 2025–Aug 2026)
- RustSec publishes seven
maliciousadvisories for the arrayref / proc-macro1 crates.io attack; Rust team confirms maintainer compromise - Xinference CVE-2026-61539: RCE via unsafe eval() in Llama3 tool-call parsing
- JSONata arbitrary-code-execution trio (CVE-2026-77413 / -77414 / -77415)
- isolated-vm ExternalCopy type-confusion sandbox escape (GHSA-864f-rcv7-6rh4)
Sections
- Ops — campaign timelines, compromise chains, and sequencing
- Tools — malware, payloads, implants, and attacker infrastructure
- Groups — crews, cluster names, and shared operational personas
- People — publicly identified individuals or project personas when public sourcing supports it
- Patterns — reusable defender heuristics
- Notes — taxonomy, usage, and editorial guidance