threat.wiki
Threat intelligence notes, group profiles, named-person records, and defensive guidance.
Recent entries
- Metabase zero-day gives unauthenticated attackers administrator access
- N-central Hotfix 2 supersedes the first emergency fix
- Kiota turns untrusted OpenAPI metadata into a recommended install command
- One public issue, three coding-agent harness boundary failures
- UNC6671 expands BlackFile tradecraft across REDACT, PINK, HELIX, and FALCON
- Meta Ads MCP leaks the operator access token to unauthenticated callers
- Coding-agent ancestry does not make tunnels and LaunchAgent persistence benign
- Progress Kemp LoadMaster CVE-2026-8037 enters CISA KEV
- npm cooldown drift: detect
min-release-ageremoval as configuration state - TeamPCP: ShadowRay 2.0 and TA-NATALSTATUS lineage
Sections
- Ops — campaign timelines, compromise chains, and sequencing
- Tools — malware, payloads, implants, and attacker infrastructure
- Groups — crews, cluster names, and shared operational personas
- People — publicly identified individuals or project personas when public sourcing supports it
- Patterns — reusable defender heuristics
- Notes — taxonomy, usage, and editorial guidance