Attackers Exploit JFrog Artifactory to Create Administrator Tokens
One firm reports attackers creating admin tokens through a critical Artifactory flaw. Self-hosted operators have six fixed-version floors to verify.
Read article →Reader view
Choose the default article length.
Nulltap™ reports on vulnerabilities, breaches, threat activity, and AI security, with practical guidance to help defenders act.
One firm reports attackers creating admin tokens through a critical Artifactory flaw. Self-hosted operators have six fixed-version floors to verify.
Read article →A crafted workspace can steer Kiro 0.7.45 from reading a local secret to placing it in a Powers registry request. Amazon fixed the reported behavior in 0.8.140.
Read article →Fire Ant hid tunnels on Cisco routers, injected TACACS servers, and planted Linux backdoors. Sygnia's artifacts show how to test each evidence plane.
Read article →CISA confirmed exploitation of a 2019 SQL Server flaw and now requires affected systems to be patched after evidence preservation and forensic triage.
Read article →PaperCut confirms active exploitation of NG and MF servers. Release 2 patches the two-flaw chain; new log and service indicators help defenders investigate exposed hosts.
Read article →StopAndProtect turns hacked WordPress sites into malware hosts, command servers, and stores for stolen files before selective ransomware deployment.
Read article →Shadowserver's retrospective Dysphoria report gives network owners 296,000 reasons to identify, rebuild, and verify compromised IoT devices.
Read article →Five newly fixed WordPress flaws expose conditional paths to admin takeover or server code execution; defenders should verify six component versions and review AJAX and account activity.
Read article →A double-read type confusion lets guest JavaScript corrupt host memory; upgrade isolated-vm 6.x to 6.2.0 or 7.x to 7.0.1.
Read article →CISA says attackers are exploiting a Linux IPv6 kernel flaw that can give a local user root and, on affected RHEL 10 systems, escape a container.
Read article →Citrix documents denial of service; separate research finds a likely SAML path to root code execution, with an important CVE-mapping caveat.
Read article →An exposed server revealed a repeatable Active Directory attack path, AI-assisted planning, Aurora lockers, and payment trails across multiple victims.
Read article →ErrTraffic lures lead users to run Cruciferra, which uses a vulnerable signed driver to terminate security processes before the Remus stealer runs.
Read article →Reader formats
Follow Nulltap by RSS or JSON, use the e-reader edition, browse the archive, or read from the terminal.
Command line
Install once, then browse, search, and read without opening a browser.
pipx install nulltappython -m pip install nulltapStart reading
$ nulltap
Browse or search
$ nulltap topics
$ nulltap search "token theft"
Use the short view
$ nulltap read 2 --short
Get help
$ nulltap --help