threat.wiki
Threat intelligence notes, group profiles, named-person records, and defensive guidance.
Recent entries
- Chainlit MCP: unauthenticated RCE and SSRF via /mcp when MCP is enabled (CVE-2026-45018 / CVE-2026-45019, fixed 2.12.0)
- Gitea diffpatch Git-hook RCE added to CISA KEV (CVE-2026-60004): repository write access installs an executable hook as the Gitea service account
- PraisonAI August 25 advisory wave: 20 flaws (CVE-2026-55522 – 55541) in PraisonAI 4.6.58 / praisonaiagents 1.6.58
- NemoClaw: malicious webpage can poison local Ollama chat templates behind NVIDIA NemoClaw (Oasis Security)
- Unit 42 State of AI-Enabled Malware — August 2026: 405 samples, only 12 in production telemetry
- JWR phishing framework: live AES-CTR WebSocket operator control, likely The Outsider variant
- Mirage2FA PhaaS: 4,500 US and EU companies hit via Microsoft 365 login-flow abuse
- Marimo CVE-2026-75149: attacker-supplied MCP command runs before cells execute in edit mode
- E4del and PINHOLE RATs use FTP banners as dead drop resolvers
- Weedhack: fake Minecraft clients and SEO poisoning deliver JAR infostealer
Sections
- Ops — campaign timelines, compromise chains, and sequencing
- Tools — malware, payloads, implants, and attacker infrastructure
- Groups — crews, cluster names, and shared operational personas
- People — publicly identified individuals or project personas when public sourcing supports it
- Patterns — reusable defender heuristics
- Notes — taxonomy, usage, and editorial guidance