logo

Critical: Splunk RCE, Arch Linux supply-chain hijack, phishing-as-a-service dismantled

ID: 8e3fb76f-b132-5973-865a-dbe699f2e40d

STIX ID: report--8e3fb76f-b132-5973-865a-dbe699f2e40d

Feed Name: defend.network

Threat Score
92/100

Date Published: 2026-06-15

Date Updated: 2026-06-21

...
...

Multiple high-severity threats: a China-linked phishing-as-a-service operation was disrupted, over 400 Arch AUR packages were hijacked to deliver a Rust infostealer and eBPF rootkit (supply-chain compromise), and Splunk Enterprise has a critical unauthenticated RCE (CVE-2026-20253, CVSS 9.8) with vendor patches available — organizations should urgently patch Splunk, audit any systems that built AUR packages, revoke and rotate developer credentials, and enforce MFA and monitoring for high-risk accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.