Overview
- Splunk
- Splunk Enterprise
Description
Statistics
- 6 Posts
Fediverse
Latest news (June 12-13, 2026): US-Iran interim deal talks advance, eyeing Strait of Hormuz reopening amid prior closure reports. SpaceX’s IPO soared past $2T on Nasdaq, marking a record. The US restricted Anthropic’s advanced AI models (Fable 5, Mythos 5) due to national security concerns. A critical Splunk Enterprise vulnerability (CVE-2026-20253) allowing remote code execution was patched.
CRITICAL: Splunk Enterprise <10.0.7/10.2.4 hit by unauthenticated RCE (CVE-2026-20253) via exposed PostgreSQL sidecar endpoints. Patch ASAP! Splunk Cloud unaffected. Exploit details are public. https://radar.offseq.com/threat/splunk-enterprise-had-an-unauthenticated-rce-sitti-a8d1c53e #OffSeq #Splunk #RCE #Vulnerability
CVE-2026-20253: How Splunk’s Unauthenticated PostgreSQL Sidecar Becomes a Pre-Auth RCE in Five HTTP Requests
CVE-2026-20253 is a CVSS 9.8 unauthenticated RCE in Splunk Enterprise. An exposed PostgreSQL sidecar endpoint lets attackers write arbitrary files and execute codehttps://thecybersecguru.com/news/cve-2026-20253-splunk-pre-auth-rce-postgresql-sidecar/
Bluesky
Overview
Description
Statistics
- 4 Posts
Bluesky
Overview
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
2026-W24 — Weekly Threat Roundup
🎯 Chinese hackers ran decade-long espionage using backdoored Linux authentication
🏫 Oracle zero-day CVE-2026-35273 exploited by ShinyHunters to ransack universities worldwide
🐧 400+ Arch Linux packages hijacked to deliver rootkit and credential stealer via npm typosquat
🤖 US government forces A…
🛠️ TECHNICAL EXPLOIT PLAYBOOK: ORACLE PEOPLESOFT CVE-2026-35273 CONTANMENT: For the engineering frontline, the CISA KEV listing above requires an immediate shift from standard patching intervals to active threat hunting. This critical missing authentication flaw within the UEM component provides unauthenticated adversaries with direct network access over HTTP to achieve full environment takeover. https://thecybermind.co/w81b
Overview
Description
Statistics
- 2 Posts
Bluesky
Overview
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
⚠️ CVE-2026-12174 (HIGH, CVSS 8.7): D-Link DCS-935L v1.10.01 has a format string vuln in /web/cgi-bin/greece/rhea. Remote attackers can exploit for code execution or DoS. No patch available — restrict device exposure. https://radar.offseq.com/threat/cve-2026-12174-format-string-in-d-link-dcs-935l-c57b0481 #OffSeq #Vulnerability #IoT
Overview
- Nefteprodukttekhnika LLC
- BUK TS-G Gas Station Automation System
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
🚨 CVE-2026-12183 (CRITICAL, CVSS 9.3): Improper authentication in Nefteprodukttekhnika BUK TS-G Gas Station Automation (2.9.1 – 2.10.2) allows remote admin takeover. Restrict access, monitor endpoints! https://radar.offseq.com/threat/cve-2026-12183-cwe-287-improper-authentication-in--13af2a78 #OffSeq #CVE2026_12183 #ICS #Infosec
Overview
- LiteSpeed Technologies
- cPanel Plugin
- WHM and cPanel PlugIn
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
⚠️ CVE-2026-54420: HIGH-severity symlink vulnerability in LiteSpeed cPanel Plugin v2.3 on CloudLinux/CageFS shared hosting. Exploited in the wild — no patch yet. Restrict FTP/web shell access & monitor for suspicious activity. https://radar.offseq.com/threat/cve-2026-54420-cwe-61-unix-symbolic-link-symlink-f-9e9ca8f9 #OffSeq #Vulnerability #LiteSpeed
Overview
- ladela
- Online Scheduling and Appointment Booking System – Bookly
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
CVE-2026-5513: HIGH severity XSS in Bookly (<=27.2) via 'bookly-customer-full-name' cookie. Exploitable if 'Remember personal info in cookies' is enabled (disabled by default). No patch yet — disable vulnerable setting! https://radar.offseq.com/threat/cve-2026-5513-cwe-79-improper-neutralization-of-in-d213c0f7 #OffSeq #XSS #WordPress #Security
Overview
- joomlacontenteditor.net
- Joomla Content Editor (JCE) extension for Joomla
Description
Statistics
- 1 Post
- 1 Interaction