threat.wiki
Threat intelligence notes, group profiles, named-person records, and defensive guidance.
Recent entries
- Reported Log4j RCE is a hardening gap, not a vulnerability — AI-agent-found FilteredObjectInputStream bypass (sonatype-2026-006746, Sonatype)
- CISA KEV August 26 additions: Citrix NetScaler DoS (CVE-2026-8452), Microsoft SQL Server RCE (CVE-2019-1068), and four UAT-10147 exploitation CVEs
- CISA AA26-237A "A Tale of Two SOCs": red team fully compromises two critical-infrastructure orgs; one detects nothing
- Unpatched Kaltura mwEmbed: unauthenticated file read + RCE (CVE-2026-19912/19913, no patch, vendor unreachable)
- NovaCookies: Docusign-notification AitM PhaaS ($320/mo) stealing Microsoft 365 sessions; Sneaky2FA variant
- SLEEPWALKER: passive raw-packet backdoor side-loaded into ESET ERAAgent.exe with a 23-instruction bytecode command language
- VMs won't contain cyber-capable agents: GPT-5.6-Cyber escapes a QEMU/KVM VM three times (Trail of Bits)
- State divergence enables unauthorized access: Provenance marker module anyone-can-pass ACL check (Trail of Bits)
- Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE chain — unauthenticated JWT-forgery-to-BDC-deserialization RCE, live in the wild, 8,500+ servers exposed (VulnCheck)
- Operation Economic Outcast: MOIS-directed critical-infrastructure cyber group designated in "Economic D-Day" sanctions
Sections
- Ops — campaign timelines, compromise chains, and sequencing
- Tools — malware, payloads, implants, and attacker infrastructure
- Groups — crews, cluster names, and shared operational personas
- People — publicly identified individuals or project personas when public sourcing supports it
- Patterns — reusable defender heuristics
- Notes — taxonomy, usage, and editorial guidance