basicsecurity.net
Proof, not just disclosure.
Threats / Contributors / Legendsec at Qi'anxin Group
Research org contributor

Legendsec at Qi'anxin Group

credited finder on 6 of 6 known-exploited records. Every aggregate on this page is recomputed from the records listed below — each one already cited to its public source.

No vendor advisory domain is cited for this contributor in the corpus — its credit here is as a CNA/finder. Home URL is a stated coverage gap.

6
records cited in
deterministic count
6
finder / reporter credits
CVE.org credits
—
CNA assignments
not a CNA
59%
avg modeled exploit prob.
FIRST EPSS, 6/6
17%
ransomware-associated
1 of 6 · CISA flag
R

Roles across the work

— find / fix / exploit / catalog, computed per record from credit type, the vendor-self-CNA gate, and the linked public exploit catalog
6
Find
record(s)
0
Fix
record(s)
0
Exploit
record(s)
0
Catalog
record(s)

Each dimension is a count of the listed records where this contributor did that job. A CNA row is fix only when the affected product is the assigner’s own; registries, coordinators, platforms, intel and research houses read as catalog, never fix. Exploit counts records where this contributor is credited as author of a public exploit / detection template in a linked catalog — we link the catalog, never host a payload.

01

Known for

— recomputed from this contributor’s own records
SurfacesServer / web platform (3), Hypervisor / virtualization (2), Operating system / kernel (1)
WeaknessMemory safety (2), Authorization / access control (2), Injection (1)
PortfolioMicrosoft (2), Apache (2), Broadcom (1), VMware (1)
PeopleNamed individuals credited under this contributor:
Xenc from SGLAB of Legendsec at Qi'anxin Group · 2Liubenjin and Zhiyi Zhang from Codesafe Team of Legendsec atzcgonvh from A-TEAM of Legendsec at Qi'anxin GroupZibo Li (@zbleet) from TianGong Team of Legendsec at Qi'anxiJiaqing Huang (@s0duku) From TianGong Team of Legendsec at Q
02

Narrative reach

— how far this contributor’s records carry an attacker, front door → lights out
1Front door
6reach this stage
→
2Keys to the kingdom
6reach this stage
→
3Lateral reach
6reach this stage
→
4Data at risk
1reach this stage
→
5Lights out
1reach this stage

Furthest any of these records carries an attacker: 5 · Lights out. 1 of 6 narrative-framed records reach data-at-risk or lights-out. (furthest-position idiom, reused from the landing map; the stage mapping is a model output over cited evidence.)

03

Recent highlights

— this contributor’s newest known-exploited records
04

Every record they’re cited in

— all 6, each linked to its cited source

This is the evidence behind every number above. Sorted ransomware-first, then by modeled exploit probability.

05

Coverage & confidence

— what this profile claims, and what it does not

Established (cited)

  • Cited in 6 known-exploited records — the list below; every one links to its public source.
  • Credited as the finder/reporter on 6 record(s) (CVE.org credits).
  • Coverage gaps — stated, not hidden

  • This profile is an aggregation: it asserts only what the listed records already cite — no new external claim about the contributor is made.
  • The TYPE badge and the narrative-stage mapping are editorial (our call), labeled as such, not a sourced fact.
  • No vendor advisory home domain is cited for this contributor in the corpus.