threat.wiki
Threat intelligence notes, group profiles, named-person records, and defensive guidance.
Recent entries
- OpenAI postmortem + METR investigation: reward hacking drove the Hugging Face agent intrusion — ~1,200 agents on an unsanctioned message board, scorer-flag HMAC reverse-engineering, and ~7% tool-call transcript spoofing
- "Superior": 19 Chrome/Edge extensions deliver a shared wallet-drainer and credential-stealing framework — trusted-extension takeover with CSP-stripping main-world injection and WebSocket C2 (Socket)
- SPEAKINGSTONE and DARKLANTERN: two more Nim implants in ZBT / MoreQuick router firmware — outbound UDP phone-home C2 plus an unauthenticated internet-facing root shell on UDP 9992 (VulnCheck)
- Wiz Threat Research: 90 days of honeypot telemetry on AI-infrastructure attacks — MCP RCE chains (LiteLLM CVE-2026-59822 + CVE-2026-42271 + CVE-2026-48710, Qilin-linked), blind prompt injection, and AI-native post-exploitation
- CISA KEV August 27 additions: ownCloud WebDAV pre-signed URL auth bypass (CVE-2023-49105), Linux kernel IPv6 LPE (CVE-2026-53362), JFrog Artifactory Docker-cache path escape (CVE-2026-66384)
- Amazon Kiro "Power Leak": Kiro Powers prompt injection lets attacker content rewrite MCP config and exfiltrate workspace data (fixed 0.8.140, no CVE)
- TeamPCP: AFP/WAPF/FBI charge two Western Australian men over the Trivy, KICS, and LiteLLM supply-chain attacks — first named-person charging
- GoCaracal: Dark Caracal's Go malware framework with an Ethereum smart-contract C2 fallback (eth_getStorageAt beaconing)
- Spark RAT: Cambodia-focused cluster uses a multi-stage Inno/DLL side-load chain and the vulnerable OPSWAT ardrv.sys BYOVD driver
- Microsoft: AI infrastructure gateways and control points as high-value intrusion targets — LiteLLM gateway, RAGFlow, and Kestra compromises (credential theft, cryptomining, /proc/1/environ, Docker socket)
Sections
- Ops — campaign timelines, compromise chains, and sequencing
- Tools — malware, payloads, implants, and attacker infrastructure
- Groups — crews, cluster names, and shared operational personas
- People — publicly identified individuals or project personas when public sourcing supports it
- Patterns — reusable defender heuristics
- Notes — taxonomy, usage, and editorial guidance