A series of security patches have been issued by Splunk to address vulnerabilities found on Splunk Enterprise, Splunk Cloud Platform, and Splunk AI Toolkit. These vulnerabilities allow low-privilege users to gain access to data with limited access, expose sensitive information by logging, and create denial-of-service (DoS) scenarios where Splunk instances might be rendered unusable. The vulnerabilities include CVE-2026-20238, CVE-2026-20239, and CVE-2026-20240. The first vulnerability (CVE-2026-20238) affects Splunk AI Toolkit releases prior to 5.7.3 owing to inadequate access control mechanisms which can permit access to AI-specific data. The second vulnerability (CVE-2026-20239) exposes sensitive data through logging operations for Splunk Enterprise and Splunk Cloud Platform. The third vulnerability (CVE-2026-20240) is related to insecure handling in coldToFrozen.sh scripts leading to the ability of attackers to induce DoS scenarios. Recommendations include updating affected releases to the latest available release, checking access control and role management, limiting access to the logs, being wary of any unusual queries, and validating backup and restore capabilities to mitigate DoS threats.
Security researchers have identified a new ransomware operation known as Payload that is actively targeting Windows and VMware ESXi environments across multiple sectors. The malwar...
Phishing operations are rapidly evolving as cybercriminals adopt encrypted messaging services such as RCS and Apple iMessage instead of relying solely on traditional SMS delivery. ...
Security researchers from GitHub Security Lab have uncovered multiple critical vulnerabilities in 7-Zip that could allow attackers to execute arbitrary code or expose sensitive inf...