threat.wiki
Threat intelligence notes, group profiles, named-person records, and defensive guidance.
Recent entries
- UNC6671 expands BlackFile tradecraft across REDACT, PINK, HELIX, and FALCON
- Meta Ads MCP leaks the operator access token to unauthenticated callers
- Coding-agent ancestry does not make tunnels and LaunchAgent persistence benign
- Progress Kemp LoadMaster CVE-2026-8037 enters CISA KEV
- npm cooldown drift: detect
min-release-ageremoval as configuration state - TeamPCP: ShadowRay 2.0 and TA-NATALSTATUS lineage
- ChainDrop: Unit 42 observes execution and live Ethereum C2 rotation
- GitHub details the guarded OpenSSF malware-advisory ingestion pipeline
- JINX-0163 / FulcrumSec cloud-native extortion cluster
- Water-sector PLC campaign: more than 4,100 internet-exposed Rockwell controllers
Sections
- Ops — campaign timelines, compromise chains, and sequencing
- Tools — malware, payloads, implants, and attacker infrastructure
- Groups — crews, cluster names, and shared operational personas
- People — publicly identified individuals or project personas when public sourcing supports it
- Patterns — reusable defender heuristics
- Notes — taxonomy, usage, and editorial guidance