Critical: Splunk RCE, Arch Linux supply-chain hijack, phishing-as-a-service dismantled
ID: 8e3fb76f-b132-5973-865a-dbe699f2e40d
STIX ID: report--8e3fb76f-b132-5973-865a-dbe699f2e40d
Feed Name: defend.network
Multiple high-severity threats: a China-linked phishing-as-a-service operation was disrupted, over 400 Arch AUR packages were hijacked to deliver a Rust infostealer and eBPF rootkit (supply-chain compromise), and Splunk Enterprise has a critical unauthenticated RCE (CVE-2026-20253, CVSS 9.8) with vendor patches available — organizations should urgently patch Splunk, audit any systems that built AUR packages, revoke and rotate developer credentials, and enforce MFA and monitoring for high-risk accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
