Splunk released fixes for CVE-2026-20253 (CVSS 9.8), a critical vulnerability in Splunk Enterprise that allows an unauthenticated attacker to create or truncate arbitrary files, leading to remote code execution. Versions below 10.2.4 and 10.0.7 are affected. Organizations should patch immediately and restrict access to Splunk management interfaces to reduce exposure.
Source: TheHackerNews
CISA adds actively exploited Oracle PeopleSoft PeopleTools bug to KEV
The U.S. Cybersecurity and Infrastructure Security Agency added Oracle PeopleSoft Enterprise PeopleTools CVE-2026-35273 (CVSS 9.8) to its Known Exploited Vulnerabilities catalog. The move signals in-the-wild exploitation and obligates US federal agencies to remediate by CISA’s deadline. Enterprises running PeopleSoft should prioritize patching, limit external exposure, and monitor for suspicious access.
Source: Security Affairs
NPM 12 to block dependency scripts by default to curb supply chain attacks
The npm client will change default behavior in version 12 so that npm install no longer executes scripts from dependencies unless explicitly permitted. The shift aims to blunt attacks that abuse preinstall/postinstall scripts to run malicious code during builds. Developers should review workflows and CI settings to allow only trusted scripts.
Source: SecurityWeek
Conti ransomware conspirator pleads guilty after extradition from Ireland
Ukrainian national Oleksii Lytvynenko pleaded guilty in the US to conspiracy to commit wire fraud tied to Conti ransomware operations. Prosecutors say he helped conduct attacks against victims worldwide, underscoring ongoing international law-enforcement pressure on major ransomware ecosystems.
Source: Security Affairs
FCC targets “burner phones” in bid to curb scams and fraud
The FCC is moving to eliminate anonymous phone usage, a step aimed at reducing robocalls, SIM swap fraud, and other abuses tied to disposable lines. The proposal raises privacy and civil liberties questions as regulators push carriers toward stronger identity checks for mobile activations.
Source: Wired
FBI builds replica small town to train for real-world cyberattacks
Inside an Alabama facility, the FBI created a small-town cyber range to simulate attacks against realistic infrastructure and services. The environment lets investigators and partners rehearse complex incidents spanning IT, OT, and critical services—improving readiness for cascading, real-world crises.
Source: TechCrunch Security
US restricts Anthropic’s Mythos 5 and Fable 5 models; company challenges decision
The US Commerce Department ordered restrictions on access to Anthropic’s Mythos 5 and Fable 5 models, prompting the company to dispute the move as lacking transparency and clear technical justification. The action signals tightening oversight of high-capability AI systems, with global implications for researchers and security teams assessing model misuse risks.
Source: Security Affairs
You May Also Be Interested In...
Amazon CEO reportedly raised Anthropic model concerns before government crackdown