Two Windows Zero-Days Give Local Attackers SYSTEM Privileges
The flaws require a local foothold, affect different Windows release families, and leave defenders with fixed-build checks but no CVE-specific compromise indicators.
Read article →Reader view
Choose the default article length.
Nulltap™ reports on vulnerabilities, breaches, threat activity, and AI security, with practical guidance to help defenders act.
The flaws require a local foothold, affect different Windows release families, and leave defenders with fixed-build checks but no CVE-specific compromise indicators.
Read article →Attackers made Coder's trusted registry serve malicious Terraform modules. Operators have a 14-hour exposure window, concrete indicators, and urgent credential work.
Read article →Google observed attackers move from cloud compromise to agent-enabled mass credential harvesting in under six hours, shrinking the time defenders have to respond.
Read article →Recovered JSCeal code replays stolen cookies and passwords through a headless browser to obtain fresh Google OAuth tokens and exposes concrete Windows hunt artifacts.
Read article →A public Telerik UI exploit chains two cryptographic oracles to unsafe type loading. Upgrade ASP.NET AJAX to 2026.2.708 and check IIS for post-exploit activity.
Read article →Every on-premises build before 2026.3.1.14 needs Hotfix 4. N-able's records conflict on exploitation, so MSPs should patch and review RMM activity.
Read article →Ten malicious OpenAPI React Query Codegen releases ran on install and carried credential-stealing code with valid provenance. Teams must scope lockfiles, rebuild hosts and rotate credentials.
Read article →Forescout ported a pre-auth PLC exploit with Claude, then bricked the device during an implant attempt. Restrict FTP and monitor crashes and outbound traffic.
Read article →Two factory firmware implants expose white-label ZBT routers through an open WAN service and an unauthenticated phone-home channel.
Read article →Zenity saw file-read probes matching CVE-2026-35029. LiteLLM advises upgrading to 1.83.0 or later; defenders should hunt configuration changes and rotate exposed secrets.
Read article →CERT Polska confirms attacks through internet-exposed SSH. Install a fixed build, restrict management access, and investigate the published log and account indicators.
Read article →StyleSmuggler turns poisoned Magento logs into server-side code execution, then hides a persistent implant outside the shop's webroot. Adobe has not issued a fix.
Read article →JetBrains confirmed that an unpatched TeamCity flaw exposed Cadence users’ code and secrets. Former users should rotate credentials and review connected systems.
Read article →Reader formats
Follow Nulltap by RSS or JSON, use the e-reader edition, browse the archive, or read from the terminal.
Command line
Install once, then browse, search, and read without opening a browser.
pipx install nulltappython -m pip install nulltapStart reading
$ nulltap
Browse or search
$ nulltap topics
$ nulltap search "token theft"
Use the short view
$ nulltap read 2 --short
Get help
$ nulltap --help