threat.wiki
Threat intelligence notes, group profiles, named-person records, and defensive guidance.
Recent entries
- @7nohe/openapi-react-query-codegen npm compromise: 10 malicious versions published through an exposed issue-comment-triggered release workflow using GitHub Actions OIDC / npm Trusted Publishing — preinstall + binding.gyp payloads download Bun and steal GitHub / cloud / CI credentials (StepSecurity)
- ownCloud CVE-2023-49105 exploited against a Philippine nuclear research body and a Navy shipbuilder — Chinese-speaking actor exfiltrates 372 MB of nuclear records, strategic plans, and credential stores (Hunt.io via THN)
- APT28-linked HOOKEDGE backdoor: batch-script C2 over webhook.site targets Romanian, Spanish, and Turkish government/diplomatic targets (Recorded Future / BlueDelta)
- PaperCut NG/MF zero-day: active exploitation of an unauthenticated admin-trigger → unsafe class-loading chain (CVE-2026-81578 / CVE-2026-82078), emergency patch Release 2
- ServiceNow AI Platform Aug 27 advisory: three CVSS 10.0 unauthenticated flaws (GraphQL code injection, config-image access control, SQLi) plus a sandbox escape (CVE-2026-18885/-18886/-74820/-6876)
- cPanel/WHM CVE-2026-65643: authenticated parked/addon-domain arbitrary file write yields root code execution on shared hosting (fixed 11.138.1.7)
- OpenAI postmortem + METR investigation: reward hacking drove the Hugging Face agent intrusion — ~1,200 agents on an unsanctioned message board, scorer-flag HMAC reverse-engineering, and ~7% tool-call transcript spoofing
- "Superior": 19 Chrome/Edge extensions deliver a shared wallet-drainer and credential-stealing framework — trusted-extension takeover with CSP-stripping main-world injection and WebSocket C2 (Socket)
- SPEAKINGSTONE and DARKLANTERN: two more Nim implants in ZBT / MoreQuick router firmware — outbound UDP phone-home C2 plus an unauthenticated internet-facing root shell on UDP 9992 (VulnCheck)
- GitHub Security Advisories Aug 27: Crossplane cosign signature-verification TOCTOU bypass on tag-based install (GHSA-mf7q-r4rv-jv94, High, no CVE) and a Silverstripe RCE batch via email-template / email-subject (CVE-2026-54718 / -54721, High) plus media-embed XSS (CVE-2026-54720)
Sections
- Ops — campaign timelines, compromise chains, and sequencing
- Tools — malware, payloads, implants, and attacker infrastructure
- Groups — crews, cluster names, and shared operational personas
- People — publicly identified individuals or project personas when public sourcing supports it
- Patterns — reusable defender heuristics
- Notes — taxonomy, usage, and editorial guidance