threat.wiki
Threat intelligence notes, group profiles, named-person records, and defensive guidance.
Recent entries
- TheHatman: Microsoft Entra tenant credential-theft and forum sale claims
- Entra ID rogue device registration and AI-generated identifiers
- GitLab GraphQL CVE-2026-19478 / CVE-2026-19650 critical patch
- vm2 NodeVM host state exposure and DNS hijack (GHSA-m5w8-4gq2-6f8x)
- npm bin-entry dependency confusion: Google-scoped bin name harvesting
- macOS ClickFix campaign: MacSync Stealer behavioral pivots and rotating infrastructure
- CISA KEV August 17–18 additions: Microsoft IKE, Ray, VMware vCenter, SharePoint, macOS
- Wiz Red Agent finds Snowflake GitHub Actions script injection leading to Jira credential exfiltration
- CloudSEK publishes TeamPCP victim dataset: 78,330 secrets from 2,186 organizations; Wiz CIRT documents multi-org PAT mass-cloning campaign
- Kimwolf v7 hardens Android/IoT DDoS operations with HTTP/2 fingerprints, ENS, and Tor
Sections
- Ops — campaign timelines, compromise chains, and sequencing
- Tools — malware, payloads, implants, and attacker infrastructure
- Groups — crews, cluster names, and shared operational personas
- People — publicly identified individuals or project personas when public sourcing supports it
- Patterns — reusable defender heuristics
- Notes — taxonomy, usage, and editorial guidance