logo

Splunk RCE, Arch Linux supply-chain hijack, Velvet Ant decade-long backdoor

ID: f0ae4c6e-7335-5bc6-b625-a7478a85c313

STIX ID: report--f0ae4c6e-7335-5bc6-b625-a7478a85c313

Feed Name: defend.network – Daily Threat Briefings

Threat Score
92/100

Date Published: 2026-06-14

Date Updated: 2026-06-14

...
...

TL;DR: Critical Splunk unauthenticated RCE (CVE-2026-20253, CVSS 9.8) requires immediate patching; over 400 Arch Linux AUR packages were hijacked to distribute a Rust credential stealer and optional eBPF rootkit compromising developer build environments; and China-linked Velvet Ant maintained decade‑long backdoors in PAM/OpenSSH enabling persistent administrative access. Urgent actions recommended: patch Splunk, audit and revoke compromised developer credentials and SSH keys, inspect and restore PAM/OpenSSH integrity, and strengthen account recovery and MFA protections against AI-enabled phishing and social-engineering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.