threat.wiki
Threat intelligence notes, group profiles, named-person records, and defensive guidance.
Recent entries
- Baileys / libsignal-node npm campaign: silent WhatsApp channel-follow abuse
- Coding-agent hooks as audit telemetry: logging every AI coding-agent tool call
- Fake TradingView macOS stealer delivered by a paid YouTube ad
- Russian auth-focused espionage: Google OAuth and WhatsApp device-link hijacking (GTIG)
- Wiz stage-2 implant analysis and DPRK infrastructure overlap in the arrayref Rust supply-chain attack
- Trusted collaboration-channel identity abuse
- JFrog expands the Rust crate compromise: internment and append-only-vec join arrayref
- Rust supply-chain attack: arrayref 0.3.10 and the proc-macro1 typosquat execute a remote payload at build time
- Elementor Pro CVE-2026-32475 unauthenticated RCE and WordPress 7.0.4 CVE-2026-65640
- Stealing reasoning traces: encrypted-reasoning replay across sessions, users, and models (arXiv:2608.09867)
Sections
- Ops — campaign timelines, compromise chains, and sequencing
- Tools — malware, payloads, implants, and attacker infrastructure
- Groups — crews, cluster names, and shared operational personas
- People — publicly identified individuals or project personas when public sourcing supports it
- Patterns — reusable defender heuristics
- Notes — taxonomy, usage, and editorial guidance