Attackers Exploit Oracle WebLogic Proxy Flaw to Reach Critical Data
CISA confirmed exploitation of a CVSS 10 Oracle WebLogic proxy flaw. Patch affected Apache and IIS plug-ins, then review requests for unauthorized data access.
Read article →Reader view
Choose the default article length.
Nulltap™ reports on vulnerabilities, breaches, threat activity, and AI security, with practical guidance to help defenders act.
CISA confirmed exploitation of a CVSS 10 Oracle WebLogic proxy flaw. Patch affected Apache and IIS plug-ins, then review requests for unauthorized data access.
Read article →An updated Android banking trojan blocks Google Play traffic, automates wireless ADB pairing, and targets 349 financial apps across 16 countries.
Read article →A 1.1 MB fake installer delivers Vidar, launches installed browsers headlessly, and copies credentials and sessions that can remain useful after cleanup.
Read article →Two exploited miniOrange SAML flaws can mint WordPress admin sessions. Seven independently versioned editions make ordinary update and vulnerability checks unreliable.
Read article →Kaspersky traced malware on DoFun-powered car displays from a trusted updater to ad fraud and a residential proxy. DoFun says it fixed the issue but published no fixed build.
Read article →The browser extension exposed vault tokens to untrusted page messages. Version 3.49.6 adds origin, frame, and nonce checks; later builds supersede it.
Read article →C2Looper shifted from one-second HTTP beacons to GitHub C2. Hunt its OneDrive DLL, JSON control files, debug marker, commands, hashes, and two IPs.
Read article →Forminator through 1.56.1 trusts forged upload settings and misses dangerous pipe-delimited MIME keys. Update to 1.57.1 and check public upload paths for executable files.
Read article →Check Point reproduced kernel file and registry operations through Defender's signed BTR.sys driver. Abuse needs admin rights; behavioral telemetry separates it from cleanup.
Read article →Gambit observed Claude Code inside six intrusions. Hunt the test VPN account, rogue LDAP listeners, backup discovery, SQL staging, and firewall restores.
Read article →Patch the missing upload check, then audit who can still reach three unresolved links in the Configuration Manager chain.
Read article →Attackers are exploiting a Zimbra SNMP flaw through crafted SMTP requests. Version 10.1.20 fixes it; exposed servers need log and file review.
Read article →A blank file entry bypasses Elementor Pro upload checks on exposed forms. Version 4.2.2 fixes the flaw, but patched sites still need to hunt for PHP left behind.
Read article →Reader formats
Follow Nulltap by RSS or JSON, use the e-reader edition, browse the archive, or read from the terminal.
Command line
Install once, then browse, search, and read without opening a browser.
pipx install nulltappython -m pip install nulltapStart reading
$ nulltap
Browse or search
$ nulltap topics
$ nulltap search "token theft"
Use the short view
$ nulltap read 2 --short
Get help
$ nulltap --help