threat.wiki
Threat intelligence notes, group profiles, named-person records, and defensive guidance.
Recent entries
- Anthropic Threat Intelligence report (September 2026, surfaced in tl;dr sec #346): seven harm areas, Dec 2025–Aug 2026 disruptions, framed by GTG designators and an uplift metric — cyber headliners: GTG-20006 (attribution consistent with Midnight Blizzard) ran an autonomous malware-rebuild-to-evade-detection loop (agents re-modified and rebuilt samples until undetected; the human mainly tuned Claude Code skills) plus a hospitality-WiFi DNS-hijack → ClickFix chain converging with Microsoft's Storm-2945/CaptiveCrunch, and stole a full military drone-vision SDK (days of AI-assisted RE into architecture/BOM/suppliers); GTG-50014 (suspected ShinyHunters affiliates): 10 EC2 workers mass-downloaded 1.8M APKs scanned with TruffleHog for hardcoded secrets, 2,100+ Azure AD token sets across 40+ tenants dumped in ~34 h ("AI agents performed nearly all of the work"), developer-token → cloud-admin in ~3 h, stole victims' AI API keys and ran follow-on attacks on the victim's keys ~3 weeks (loot/compute/cover), even cashed $2k/$5k HackerOne bounties from companies they extorted (PhantomRaven convergence); GTG-10007 Changsha "exploit foundry" — Chinese-speaking operators incl. undergraduates ran standing agent-swarm vuln research against an endpoint-security product (multiple validated unknown vulns + working appliance exploits, a dozen-plus possible zero-days in one month) with persistent cross-session campaign memory; GTG-50020 prompt-injected an AI vendor's automated evaluation sandbox into handing over its customers' production AI API keys, then attacked ~30 AI companies in ~4 days repeating one working path (goal: pre-release Claude access — never achieved; Anthropic's systems never breached); GTG-50029 lone hacktivist discovered+debugged an undocumented WordPress re-installation race condition (rogue admin with no credentials, 4+ sites), poisoned a victim's backups so restores re-infect, and built containerized doxing platform "fafsearch"; distillation section names Alibaba/Qwen (151M+ exchanges, CoT-extraction prompt into Qwen 3.5/3.6/3.7), Moonshot (served Claude to users who thought it was Kimi, 23M+), DeepSeek (12.1M+), Zhipu (3.4M+, CTF campaign vs US frontier models' cyber capabilities pre-GLM 5.3), Xiaomi (replayed its own users' MiMo sessions, 400k+), SenseTime (bought harvested transcripts) and MiniMax (shell-company proxy) — with countermeasures: reasoning summarization before responding + Fable 5.1 preserved thinking. Headline: "sophisticated attacks no longer require sophisticated attackers"; "security through obscurity is no longer viable" (Anthropic, Sep 17, 2026)
- Sansec Forensics: Brevo supply-chain attack — a breach of messaging/marketing provider Brevo (Sendinblue; clients incl. eBay, Louis Vuitton, Michelin) poisoned its own served JavaScript on Sep 14 (16:05–20:13 UTC), reaching 100,000+ customer sites through the two scripts merchants embed (
cdn.brevo[.]com/js/sdk-loader.js,brevo-conversations.js) plus Brevo's own pages, booking pages, hosted forms/unsubscribe pages, and the chat-widget iframe — one appended IIFE loadingf.jsfrom attacker-createdcdn*.sendibt1[.]comsubdomains (a legitimate Brevo domain; the Aug-25 CT-dated cert proves DNS write access weeks earlier; Maltrail even blocklisted the legitimate apex and retracted it — block the cdn* records only). Two victim classes from one payload: logged-in WordPress admins visiting their own site got a plugin silently installed through their own session (cdn10.sendibt1[.]com/p/wm.zip→/wp-admin/update.php?action=upload-plugin; unrecovered, suspected backdoor — hunt Sep-14 upload-plugin POSTs and compare disk plugins vs the admin screen), and everyone else (visitors + campaign recipients clicking unsubscribe links) got a ClickFix "verify you are human" overlay fetching the clipboard command from/api/v1/4aff112?tk=with per-session tokens, event beacons, and a fixed cloak response{"s":0,"r":"https://www.google.com"}for scanners. Root-cause hypothesis (unconfirmed by Brevo): compromised Cloudflare account across Brevo's five apex DNS zones — poisoned files kept identicalLast-Modifieddates = edge rewrites, not a deploy; last CSP report arrived 21 h after origin cleanup (cache persistence again). All malicious hosts NXDOMAIN since Sep 15; no actor named; separate Sep 10 SAML-SSO incident (138 accounts) unlinked (Sansec, Sep 16; BleepingComputer/Cybernews/CyberInsider Sep 17, 2026) - Kaspersky GReAT: MovieReaper — a previously unknown modular 4-stage Windows trojan framework distributed by trojanizing movie torrents (incl. "The Odyssey" 2026) through the compromise of itorrents[.]org, a shared public torrent-file repository many trackers draw from — one upstream poisoning reaches users of multiple trackers without touching them, and the archive remains compromised as of publication. Chain: decoy
odyssey (2026)...exeloader (one shared MD5 across all names; no LoadLibrary/GetProcAddress — PEB Ldr walk + manual export parsing for anti-sandbox) → shellcode fragments over plain HTTP at image-like paths, RWX via a VEH debug-break trick into a rawNtProtectVirtualMemorysyscall,EtwpCreateEtwThreadexecution → stage 2 fetches the next C2 address from a Solana mainnet account's data field via public RPC (account6pnDG...nLDm, write programCSiY8...wHtL) = takedown-resistant rendezvous, TLS-pinned nanopb protobuf beacon → UAC bypass + persistence asProgramData\Microsoft\Windows\Telemetry\msedge.exe→ 21-command "file manager" implant with arbitrary COFF-module loading (extendable server-side). Several hundred victims, individuals + orgs (RU/TR/JP/KE/UG/CO/ES/NL/BE/DE/FI/TZ/GH/NP), same actor back to Oct 2025. Kaspersky's disruption read: stage 1 is the choke point (single domaindeadhub[.]org+ single IP), stage 2 is built to survive IP blocklisting — but the Solana account/program addresses are durable identifiers to monitor on-chain (Kaspersky GReAT, Sep 17, 2026) - GitHub Actions
cache-modenow GA (Sep 10, covered by Socket Sep 16): least-privilege access to the Actions cache at workflow/job level, aimed squarely at the cache-poisoning technique behind recent npm/PyPI supply-chain compromises — low-trust triggers likepull_request_targetnow default to read-only cache access,pushdefaults to write, job level overrides workflow level, and the mode is enforced by the cache service and carries through reusable workflows (a called workflow can't exceed its caller's grant). The risky line is the explicit declaration:cache-mode: write/write-onlyon a low-trust event overrides the safe default and now earns a warning annotation — treat that annotation as a detection finding. Durable caveat:cache-modecloses one store, not the class — artifact uploads, dependency-proxy and self-hosted-runner state remain reachable poisoning surfaces (GitHub Changelog / Socket, Sep 10–16, 2026) - OX Security root-cause teardown: four unauthenticated-critical CVEs landed in one 24-hour window (advisories Sep 8, write-ups Sep 14) — one shared failure, "a component trusting the layer next to it": Netty CVE-2026-75595 (CVSS v4 9.1) — the ClientHello bounds check is computed five bytes short (ignores the 5-byte TLS record header), so a legal fragmented ClientHello raises
IndexOutOfBoundsExceptionand the generic handler answers by selecting the defaultSslContext— an unauthenticated mTLS bypass wherever per-SNIclientAuth=REQUIREis the sole gate and the fallback is permissive; fixed 4.1.137 / 4.2.17.Final but the fail-openselect(ctx, null)handler itself REMAINS — and GitPython CVE-2026-78676 (CVSS 9.8, fixed 3.1.59) — a dormant, spec-compliant multi-line config value (zzz = "A\nhooksPath = ../evil-hooks\") is inert for real git, but GitPython's writer emits embedded newlines unquoted with no continuation backslash, so the next unrelated config write re-serializes it into two options — livecore.hooksPath→ code execution on the next git operation; theUNSAFE_CONFIG_CHARS_REguards from FOUR earlier config-injection GHSAs only checked write arguments, never values that entered via_read()from disk; the two Next.js RCEs in the same cluster carry their newly disclosed Windows mechanism (incremental-cache path join escapes every delimiter except the literal backslash, so route segments escape the cache dir on Windows only, disclosing the Server Actions encryption key) - CrowdStrike Counter Adversary Operations: PhantomRaven — an LLM-generated JavaScript infostealer (high-confidence token-analysis + placeholder-code assessment, author sophistication likely low) distributed through typosquatted npm packages whose operator is a self-proclaimed bug bounty hunter (Bugcrowd/Intigriti/YesWeHack/HackenProof/HackerOne, bounties from ≥9 entities): infect targets via the npm supply chain, then email the victim "discovering" the compromise and collect a bounty for the manufactured finding — the disclosure economy inverted. Delivery = clean placeholder package + HTTP-URL remote dynamic dependency (
npm[.]jpartifacts[.]com) whose fetched payload carries apreinstallscript — precisely the path npm v12's June 2026 install-script blocking shuts (on npm ≥12 the script is blocked pendingnpm install-scripts approve); publishersjpdhellonpm1(transform-jsbi-to-bigint) +jpd15(sort-imports-es6-autofix) both now0.0.1-security= taken down; collection = Git/npm config creds + CI/CD env vars for GitHub Actions, GitLab CI, Jenkins, CircleCI; no log-shop sales observed — output feeds bounty submissions. Durable read: a "responsible disclosure" email citing npm dependency confusion can itself be attack stage two — verify compromise claims with independent IR before engaging (CrowdStrike, Sep 15, 2026) - Mandiant IR case study (AI Risk and Resilience Report 2026, reported Sep 16, 2026): an attacker hijacked an ACTIVE AI coding-assistant session at an unnamed SaaS provider and turned the assistant into a trojan horse — it recommended an attacker-poisoned package, the recommendation was accepted, and through the live session the attacker installed an infostealer via a poisoned PyPI package, harvested GitHub OAuth tokens, and deployed the self-spreading Shai-Hulud worm across ~100 internal repositories (automated secret theft + programmatic source-code exfiltration), then poisoned a package in the victim's own official namespace causing a second infection when a colleague pulled it. First IR-documented case of the trusted-interpreter failure — the AI's recommendation is the new phishing click; the hijack method and timing are undisclosed. Mandiant's controls: checksum + allowlist verification hooks on AI-recommended dependencies, isolated/just-in-time local credentials, egress routed through internal registries only, and treating coding assistants and MCP servers as privileged sessions (Mandiant / The Hacker News, Sep 16, 2026)
- CISA KEV Sep 16 batch is three additions, not one (catalog 2026.09.16, 1,713): Cisco ISE / ISE-PIC CVE-2026-76460 (CVSS 10.0, CWE-648) — unauthenticated crafted API request bypasses web-management authentication, and Cisco's own advisory says successful exploitation may yield root command execution, PSIRT "aware of active exploitation", no workarounds (iACL the management interface), fixed 3.1 P12 / 3.2 P11 / 3.3 P12 / 3.4 P7 / 3.5 P4 with 3.0 EoS = no fix; hunt
access.logon EVERY node for suspicious usernames (| include dummyuser) and re-image — a root attacker hides evidence; root on ISE = the network admission control brain for every downstream authenticated network. Plus Acronis Backup for cPanel & WHM / Plesk CVE-2026-87886 (7.8, CWE-276) — default-permission local privilege escalation under limited, targeted exploitation, fixed 1.9.3 HF3 / 1.8.11; on shared hosting one phished site account + this LPE = all tenants' backups and workloads. Both BOD due 2026-09-19 (CISA / Cisco / Acronis, Sep 16, 2026) - Check Point emergency alert sk1000155 (Sep 16, 2026): CVE-2026-91843 (CVSS 9.8) — a stack overflow during the UNAUTHENTICATED login process on Security Management / Multi-Domain Security Management / Log Servers allows remote code execution as root; the fix ships only as an urgent LivePatch bundle (validate with
cplp list→fwm:fwm armed livepatch CVE-2026-91843), and Check Point publishes the hunt tell itself: SmartConsole audit logs reading"Administrator failed to log in: Username too long"= login-path overflow probing; R81.10/R81/R80.x are EoS with no fix package; Smart-1 Cloud not affected; owning the management server = owning every gateway it governs (third September management-plane root flaw after Cisco FMC + Secure Email Gateway) - @zereight/mcp-gitlab CVE-2026-61560 (CVSS 9.8, advisory Sep 16, 2026): the most-adopted community GitLab MCP server (~82k npm downloads/week) shipped its documented Docker default as an unauthenticated privileged proxy —
SSE=trueexposes ~100+ tools on/sse+/messageswith zero auth (andREMOTE_AUTHORIZATIONis explicitly incompatible with SSE mode), while default-onupload_markdowndoesfs.readFileSyncon any attacker path and uploads it through the legitimate GitLab uploads API — one anonymous chain: read/proc/self/environ→ fetch it back from GitLab → stealGITLAB_PERSONAL_ACCESS_TOKEN→ full account takeover (container runs as root, port bound 0.0.0.0); patched 2.1.27 + setSSE_AUTH_TOKEN— and the repo advisory list shows CVE-2026-61560 is one of SIX advisories on this package in ~10 weeks: SSRF via theX-GitLab-API-URLheader attaching the victim'sPrivate-Tokento attacker-chosen hosts (CVE-2026-61559), DNS rebinding to the local Streamable-HTTP transport with no Host/Origin validation (CVE-2026-61568),execute_graphqldefeating BOTH read-only mode andGITLAB_ALLOWED_PROJECT_IDS(reviewed on 2.1.28 — after the 2.1.27 "fix"), raw-job_idtraversal to arbitrary/api/v4/endpoints, and adownload_release_assetpath escape tested on 2.1.30; siblings express fixes only as vulnerable ranges (< 2.1.30,< 2.1.32,< 2.1.41) — effective floor ≥ 2.1.41; run the newest release, not a pinned "patched" version, and rotate the PAT if you ran any default deployment
Sections
- Ops — campaign timelines, compromise chains, and sequencing
- Tools — malware, payloads, implants, and attacker infrastructure
- Groups — crews, cluster names, and shared operational personas
- People — publicly identified individuals or project personas when public sourcing supports it
- Patterns — reusable defender heuristics
- Notes — taxonomy, usage, and editorial guidance