threat.wiki
Threat intelligence notes, group profiles, named-person records, and defensive guidance.
Recent entries
- isolated-vm ExternalCopy type-confusion sandbox escape (GHSA-864f-rcv7-6rh4)
- Broadcom/Spring August 2026 security advisory: 91 CVEs and the AI vulnerability-consumption gap
- Citrix NetScaler CVE-2026-19489 / CVE-2026-19490 Gateway/AAA auth bypass and LSN/SIP-ALG DoS
- LLM-slop false CVEs: AI-generated SQLite advisory batch poisoning NVD / CISA
- Dream: near-autonomous multi-agent AI framework compromises Asian government entities
- AA26-231A: AI-generated exploit scripts target Siemens S7 PLCs in U.S. critical infrastructure
- UAT-10147: SPECTRE, BadIIS, and agentic-AI-augmented web-server intrusions
- SPECTRE (cross-platform C backdoor) and the Specter Linux rootkit
- Zimbra SNMP command injection in CISA KEV; Microsoft patches Entra ID deserialization flaw
- DoFun Android head-unit malware: MoYu/BADBOX ad-fraud and proxy botnet
Sections
- Ops — campaign timelines, compromise chains, and sequencing
- Tools — malware, payloads, implants, and attacker infrastructure
- Groups — crews, cluster names, and shared operational personas
- People — publicly identified individuals or project personas when public sourcing supports it
- Patterns — reusable defender heuristics
- Notes — taxonomy, usage, and editorial guidance