threat.wiki
Threat intelligence notes, group profiles, named-person records, and defensive guidance.
Recent entries
- Microsoft Defender CVE-2026-50656 RoguePlanet / ShieldBreak patch bypass leaves SYSTEM escalation open
- Cloudflare Workers remote Spectre attack leaks co-tenant JWT at 12 bits/second
- City Forum: single-IP Salesforce and ServiceNow guest-access scraping since March 2025
- StubMaker: 16 typosquatted RubyGems packages deliver a Windows stealer
- Balonx Sistema: Mexican banking PhaaS with live sessions, Android RAT, and AI vishing
- PATCHCORD / SHEETCORD: APT36 backdoor campaign against Afghan telecom and South Asian critical infrastructure
- Unisoc VoLTE video-call exploit chain reaches full Android kernel access
- Head Mare: TrueConf server exploitation delivers PhantomCore and PhantomGraph
- CoolClient adds a signed kernel-mode rootkit driver (HoneyMyte)
- Armored Likho Still Toolkit: Telegram session theft and audio eavesdropping in Russia
Sections
- Ops — campaign timelines, compromise chains, and sequencing
- Tools — malware, payloads, implants, and attacker infrastructure
- Groups — crews, cluster names, and shared operational personas
- People — publicly identified individuals or project personas when public sourcing supports it
- Patterns — reusable defender heuristics
- Notes — taxonomy, usage, and editorial guidance