BlueMoon Exploit Kit Breaks Out of Chrome to Deploy Espionage Malware
Four espionage groups used a shared Chrome-to-Windows exploit chain. Build checks show current exposure; campaign artifacts support a separate compromise hunt.
Read article →Reader view
Choose the default article length.
Nulltap™ reports on vulnerabilities, breaches, threat activity, and AI security, with practical guidance to help defenders act.
Four espionage groups used a shared Chrome-to-Windows exploit chain. Build checks show current exposure; campaign artifacts support a separate compromise hunt.
Read article →More than 100 malicious gems used RubyDoc documentation builds to execute supplied code. Maintainers should review package and account changes tied to legacy API keys.
Read article →CISA confirms exploitation of CVE-2026-84869. ScreenConnect clients before 26.6.5 can transfer and run files through active sessions without authorization or host confirmation.
Read article →An exploited GitLab flaw exposes arbitrary server files through the commits API. Self-managed operators should install 19.1.8, 19.2.6, or 19.3.2 immediately.
Read article →CloudSEK found BigBear 2.0 stealing Microsoft 365 session cookies after MFA. Revoke sessions, rotate credentials and require phishing-resistant sign-in.
Read article →AOMEI Backupper 8.4.0 exposes physical-disk writes to local users. Without Secure Boot, attackers can plant UEFI code that runs before Windows defenses.
Read article →Two certificate-processing flaws reach gateways and management servers. Fixed takes and LivePatch output give operators a direct protection check.
Read article →Attackers used Cisco Secure FMC flaws to reach root, steal credentials, tunnel into networks, deploy Cyclops Blink, and encrypt selected endpoints with Qilin.
Read article →Kestra OSS versions through 1.3.20 let unauthenticated requests create workflows and run commands as root inside workers. CISA confirms exploitation.
Read article →Chrome 153 fixes exploited V8 out-of-bounds write CVE-2026-87491 across desktop and Android. Fleet owners should verify running builds; Google published no attack indicators.
Read article →CISA confirmed exploitation of CVE-2025-25249 across FortiOS, FortiSwitchManager and FortiSASE, with federal remediation due September 12.
Read article →CISA now links CVE-2025-14733 to ransomware. Patch exposed Fireboxes, check WatchGuard's indicators, and rotate locally stored secrets after confirmed activity.
Read article →Customer-managed VPN and AAA appliances need branch-specific fixed builds; configuration determines exposure on later NetScaler releases.
Read article →Reader formats
Follow Nulltap by RSS or JSON, use the e-reader edition, browse the archive, or read from the terminal.
Command line
Install once, then browse, search, and read without opening a browser.
pipx install nulltappython -m pip install nulltapStart reading
$ nulltap
Browse or search
$ nulltap topics
$ nulltap search "token theft"
Use the short view
$ nulltap read 2 --short
Get help
$ nulltap --help