Skip to content
Product
Use it
Threat intelligence API
Free key, 70+ endpoints, OpenAPI. The product.
Get started
Pick your stack, make your first call.
Live feed
The console: incidents, filters, entities, search.
Recipes
Runnable examples for the free key.
Free feeds
RSS, ransomware feed, IOC blocklist, MISP — no key.
CLI & agents
tc from a terminal; agent keys with scoped budgets.
The data
Incident records
900 articles a day become ~70 scored incidents.
Dark web
First-party leak-site collection: victims, groups, markets.
Validated IOCs
Indicators with a false-positive gate; STIX, MISP, CSV.
Vulnerabilities
CVEs with EPSS, KEV and exploit status.
Entity graph
Actors, malware, CVEs, companies — pivotable.
For teams
For service providers
Per-client feeds, alerts and branded digests.
Use cases
How teams and builders use the corpus.
About ThreatCluster
What it is and how it is built.
Pricing
Docs
Reference
OpenAPI (Swagger)
Every endpoint, parameter and response model.
ReDoc
The same reference, long-form.
Examples on GitHub
curl, Python and Node quickstarts; daily spec snapshot.
Guides
Quickstart & plans
Key, scopes, budgets, tiers.
Integrations
Splunk, Sentinel, Elastic, agents and terminals, step by step
Export formats
STIX 2.1, MISP, CSV, text.
CLI setup
Install, log in, wire an agent.
No results found
Sign in
Get a free key
No results found
Product
Threat intelligence API
Get started
Live feed
Recipes
Free feeds
CLI & agents
The data
Incident records
Dark web
Validated IOCs
Vulnerabilities
Entity graph
For teams
For service providers
Use cases
About ThreatCluster
Docs
OpenAPI (Swagger)
ReDoc
Examples on GitHub
Quickstart & plans
Integrations
Export formats
CLI setup
Pricing
Contact
Get a free key
Sign in
Back
Spectre
Vulnerability
Threat entity extracted from intelligence sources
Entities
›
vulnerability
›
Spectre
Frequency
21
occurrences
First Seen
November 11, 2025
Last Seen
September 1, 2026
API
Overview
Recent Events
Profile
Profile
MITRE ATT&CK
1 / 2
Associated Malware
BadIIS
Gh0stCringe
NoodleRat
QuasarRAT
Specter
Tools Used
Tcpdump
Certutil
Curl
DeepAudit
Havoc Framework
JavaScript
Metasploit Framework
Meterpreter
MITRE Techniques
T1071 - Application Layer Protocol
T1505.003 - Web Shell
T1003 - OS Credential Dumping
T1567 - Exfiltration Over Web Service
T1055.012 - Process Hollowing
T1041 - Exfiltration Over C2 Channel
T1053 - Scheduled Task/Job
T1055 - Process Injection
Campaigns
Whisper Leak
Affected Platforms
Linux
Risc-v
Windows
Cloudflare Workers
SiFive P550
V8
Regions
Germany
Vietnam
Belgium
Bolivia
Brazil
Sectors Affected
Gaming
Government
Media
Technology
-
REC
Recon
No techniques detected
-
RD
Resource Dev
No techniques detected
1
IA
Initial Access
T1190 - Exploit Public-Facing Application
3
EX
Execution
T1053 - Scheduled Task/Job
T1059.001 - PowerShell
T1203 - Exploitation for Client Execution
3
PE
Persistence
T1505.003 - Web Shell
T1543.003 - Windows Service
T1547 - Boot Or Logon Autostart Execution
1
PE
Priv Esc
T1055.012 - Process Hollowing
2
DE
Defense Evasion
T1112 - Modify Registry
T1562.001 - Disable Or Modify Tools
1
CA
Cred Access
T1003 - OS Credential Dumping
1
DI
Discovery
T1057 - Process Discovery
-
LM
Lateral Mov
No techniques detected
-
CO
Collection
No techniques detected
1
C2
C2
T1071 - Application Layer Protocol
2
EX
Exfil
T1567 - Exfiltration Over Web Service
T1041 - Exfiltration Over C2 Channel
-
IM
Impact
No techniques detected
16
techniques detected across
9
tactics
Related Clusters (13)
Google and Apple Issue Security Updates for Zero-Day Vulnerabilities
Dec 12
·
8 sources
84
UAT-10147 Cybercrime Group Integrates AI for Large-Scale Attacks
Aug 20
·
10 sources
75
UAT-10147 Threat Actor Deploys SPECTRE Backdoor with AI and EDR Bypass Techniques
Aug 24
·
2 sources
73
SVG Phishing Campaign Exploits Email Security Gaps
Jun 2
·
3 sources
71
New TONTOU Attack Exploits Spectre v2 Defenses on Intel and AMD CPUs
Aug 7
·
7 sources
71
AI-Driven Exploit Bypasses Apple's M5 Security in Days
May 14
·
28 sources
70
Nightmare-Eclipse Banned from GitHub and GitLab for Zero-Day Exploits
May 27
·
124 sources
68
Cloudflare Workers Vulnerability Exploited by Faster Spectre Attack
Aug 20
·
5 sources
68
RISC-V Processors Found Vulnerable to Spectre Attacks
Aug 12
·
4 sources
68
MIT Uncovers Security Flaws in Apple M1 Chip
May 25
·
2 sources
68
Emerging Threats from Self-Evolving Malware and AI Safety Research
Sep 1
·
2 sources
52
LLM Side-Channel Attack Exposes User Conversations
Nov 11
·
2 sources
22
LLM Side-Channel Attack Exposes User Conversations
Nov 11
·
2 sources
5
Prev
1 / 3
Next
Related Articles (21)
Editors Choice
theguardrail.net
·
Sep 1
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
Thehackernews
·
Aug 24
UAT-10147 SPECTRE Uses Linux Rootkit and BYOVD
Socprime
·
Aug 21
Safe In The Sandbox Security Hardening For Cloudflare Workers
blog.cloudflare.com
·
Aug 20
Cloudflare Workers Spectre Exploit Stole Auth Tokens 360× Faster Than Prior Attack
Techtimes
·
Aug 20
Researchers demonstrate faster remote Spectre attack against Cloudflare Workers
Feeds.Feedburner
·
Aug 20
UAT-10147 deploys SPECTRE: A cross
Blog.Talosintelligence
·
Aug 20
UAT-10147: Chinese-speaking adversary integrates agentic AI into post
Blog.Talosintelligence
·
Aug 20
Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second
Thehackernews
·
Aug 19
A revisit of remote Spectre attacks on Cloudflare Workers
News.Ycombinator
·
Aug 19
Gerlach
www.usenix.org
·
Aug 13
Spectre vulnerabilities found on commercial RISC-V chips | brief
Scworld
·
Aug 13
Spectre rears its ugly head again as researchers show some RISC
Theregister
·
Aug 13
MIT boffins' TONTOU attack slips through Spectre defenses on Intel and AMD CPUs
Theregister
·
Aug 7
RFC 9239, published in May 2022
www.rfc-editor.org
·
Jun 2
Vulnerability Embargos Are Dead
jericho.blog
·
May 28
MIT Researchers Discover Flaws in the Apple M1 SoC
Electropages
·
May 25
Memory Integrity Enforcement
security.apple.com
·
May 14
Google and Apple have urgently released updates that should close security "holes" after ...
Dev.Ua
·
Dec 13
LLM side-channel attack could allow snoops to guess topic
Theregister
·
Nov 11
LLM side-channel attack could allow snoops to guess what you're talking about
Theregister
·
Nov 11
Prev
1 / 5
Next
Related Entities
Malware
Data Breach
Man-in-the-Middle
Zero-day Exploit
DDoS
Side-channel attack
Whisper Leak
Adobe Systems Incorporated
AMD
Apple
AWS
Azure