Jun 19 · Industry News

A Critical Splunk Flaw Just Made Its First-Ever Appearance on CISA’s Exploited List

Corroborated against Splunk’s own security advisory, CISA’s KEV catalog, and vendor sources, today’s brief leads with a critical, actively exploited flaw in Splunk Enterprise. Also covered: a stealthy ransomware C2 hidden inside Microsoft Teams, a major WordPress botnet takedown, and two acquisitions reshaping the identity-security market.

★ Top Read

A critical Splunk Enterprise vulnerability, CVE-2026-20253, is being exploited in the wild — an unauthenticated remote code execution path through an exposed PostgreSQL sidecar endpoint, with public proof-of-concept code already circulating. CISA added it to its Known Exploited Vulnerabilities catalog on June 18, the first-ever Splunk entry, giving federal agencies until June 21 to patch. It’s a sharp reminder that even the platforms built to deliver visibility have to be patched and watched like anything else.

Sources: SecurityWeek, Splunk Security Advisory, CISA KEV

Vulnerabilities & Exposure

Splunk Enterprise RCE actively exploited. Splunk’s advisory (SVD-2026-0603) describes a missing-authentication flaw in the PostgreSQL sidecar service endpoint that lets any network-reachable, unauthenticated user create or truncate arbitrary files; researchers at WatchTowr chained it to full unauthenticated remote code execution and published proof-of-concept code two days after disclosure. It affects Splunk Enterprise 10.2 before 10.2.4 and 10.0 before 10.0.7. Patches shipped June 10, and Splunk’s PSIRT confirmed limited exploitation on June 18. CISA’s first-ever Splunk entry on its Known Exploited Vulnerabilities catalog carries a June 21 deadline for federal agencies.

AI Impact on Security

Securing non-human and AI-agent identities is now where the money is. Two acquisitions in the same week — SailPoint acquiring Entro for non-human identity, and 1Password acquiring Apono for just-in-time access governance covering humans, machines and AI agents — signal that the identity perimeter is being redrawn around machine and agent credentials.

So what: “Agent-aware security” keeps resolving down to identity plus visibility: knowing which agent did what, with which credential, against what data. That’s a data-foundation problem before it’s an AI problem.

Cyberattacks & Breaches

DragonForce hides ransomware C2 inside Microsoft Teams relays. Symantec attributed a new Go-based backdoor, “Backdoor.Turn,” to the DragonForce group, used in a December 2025 intrusion at a major U.S. services firm. It tunnels command-and-control traffic through legitimate Microsoft Teams relay infrastructure and went undetected for roughly two months. Its capabilities include command execution, Active Directory and LDAP enumeration, lateral movement using stolen credentials, and browser credential theft.

SocGholish botnet takedown cleans up 15,000 WordPress sites. A coordinated effort dismantled the SocGholish (FakeUpdates) infrastructure and remediated roughly 15,000 compromised WordPress sites that had been pushing fake-update lures to deliver follow-on malware.

INC ransomware-as-a-service maturing fast. Researchers charted INC’s evolution into one of 2026’s more prolific ransomware-as-a-service operations, with several hundred claimed victims since 2023 and increasingly professionalized affiliate tooling. Victim counts are operator and research claims, not independently audited.

So what: The two stories that matter most today both turn trusted infrastructure into the attack path — our own Splunk sidecar service and Microsoft’s Teams relay traffic. You can only catch “logging in, not breaking in” and SaaS-tunneled command-and-control if you have telemetry across the full data foundation, not just endpoint alerts.

Regulatory & Policy

CISA’s BOD 26-04: risk-based patching with a three-day clock for the worst. CISA’s new Binding Operational Directive, issued June 10, requires federal civilian agencies to prioritize remediation based on four factors — asset exposure, KEV status, exploit automation, and post-exploitation impact. Vulnerabilities that hit all four must be fixed within three days plus forensic triage, with full program alignment due by December 7, 2026. The Splunk KEV deadline is BOD 26-04 in action.

So what: Federal patching is moving from fixed timelines to exploitability-and-impact triage, and the wider contractor ecosystem will inherit it through procurement. Agencies can’t hit a three-day fix-plus-forensic-triage window without continuous visibility into exposure and exploitation.

← All Industry News