Cybersecurity Daily: News & Threats
(00:00:00) Splunk RCE Exploited & Icarus OAuth Attack Hit CRM Data (00:00:37) CVE-2026-20253 Exploit Chain (00:01:49) Klue OAuth Token Compromise (00:02:33) Why OAuth Tokens Bypass Defenses (00:03:06) SaaS Supply Chain Scale (00:03:27) What To Watch Now A critical Splunk Enterprise vulnerability is now confirmed under active exploitation — and the implications reach far beyond a single server. CVE-2026-20253 carries a CVSS score of 9.8 and enables unauthenticated remote code execution through an unprotected PostgreSQL sidecar service. Federal agencies face a June 21 patch deadline, but organisations running vulnerable versions before Splunk's June 10 advisory may already be compromised. Because Splunk sits at the centre of security visibility — indexing logs, feeding detection pipelines, holding credentials — a successful intrusion lets attackers see what your security team sees, erase forensic evidence, and move laterally at scale. Running in parallel, threat actor Icarus used a stolen legacy credential to compromise OAuth tokens at competitive intelligence vendor Klue. Those tokens gave Icarus legitimate, passwordless access to the Salesforce environments of Huntress, Jamf, Recorded Future, and Tanium — running automated data extraction loops for 24 hours without triggering alarms. Salesforce wasn't breached; trusted OAuth tokens were simply abused. Integration service accounts held broad permissions with no MFA, no behavioural baseline, and no rotation cadence to limit a stolen token's useful life. Together these stories illustrate the defining challenge of modern enterprise security: third-party breaches now account for 30% of all incidents, doubled year-over-year. One compromised vendor credential can simultaneously unlock multiple downstream customers. The attack surface isn't a firewall gap — it's the trusted integrations organisations rely on every day. Key indicators to hunt: unusual PostgreSQL connection parameters in Splunk, unexpected database dumps, outbound Splunk connections to unknown hosts, and unreviewed OAuth token grants across SaaS integrations. This episode includes AI-generated content.
72 jaksot
Kommentit
0Ole ensimmäinen kommentoija
Rekisteröidy nyt ja liity Cybersecurity Daily: News & Threats-yhteisöön!