threat.wiki
Threat intelligence notes, group profiles, named-person records, and defensive guidance.
Recent entries
- Grafana MCP turns a caller-selected destination into a readable SSRF proxy
- LangGraph namespace prefix matching crosses tenant boundaries
- Aeternum turns Polygon smart contracts into a durable botnet control plane
- Gunra affiliates turn Fortinet and VDI access into cross-platform double extortion
- DeadLock ransomware decentralizes recovery chat and leak infrastructure
- Six npm packages use the NullReceiver Ethereum dead-drop loader
- Flyto2 sends its internal runner secret to a caller-selected callback
- Metabase zero-day root cause and downstream customer-data impact
- OpenAI pauses insufficiently isolated Astra work after it cannot rule out a critical cyber threshold
- ChainDrop reaches the MCP Registry through a poisoned source repository
Sections
- Ops — campaign timelines, compromise chains, and sequencing
- Tools — malware, payloads, implants, and attacker infrastructure
- Groups — crews, cluster names, and shared operational personas
- People — publicly identified individuals or project personas when public sourcing supports it
- Patterns — reusable defender heuristics
- Notes — taxonomy, usage, and editorial guidance