Splunk’s Security Data Could Be Damaged Without a Login

An exploited Splunk Enterprise flaw let unauthenticated attackers create or truncate arbitrary files through a PostgreSQL sidecar endpoint.

An exploited Splunk Enterprise flaw let unauthenticated attackers create or truncate arbitrary files through a PostgreSQL sidecar endpoint.

Cisco ISE's critical command injection required an administrator, while the lower-scored flaw exposed hashed credentials without authentication.

Australia’s critical-infrastructure framework combines mandatory risk management and incident reporting with last-resort government powers to act during a serious cyber incident. Australia has expanded the Security of Critical Infrastructure Act in several waves. Major reforms in 2021 and 2022 broadened…

Cisco confirmed exploitation of two Catalyst SD-WAN control-plane flaws and told customers to preserve admin-tech evidence before patching or changing configuration.

The WAF Blocked the Name. The Attacker Changed the Spelling. Update, 29 September 2026: Google’s 25 September report describes renewed ShinyHunters exploitation of CVE-2026-35273 across sectors. The group changed its request paths to bypass WAF rules protecting PeopleSoft’s Environment Management…

A SimpleHelp OIDC bypass could create technician accounts, enrol attacker-controlled MFA and inherit remote-management permissions from a mapped group.
Unauthorised access to a World Food Programme registration system exposed data associated with roughly 600,000 Gaza households. In a conflict zone, ordinary identity and location fields can create extraordinary physical risk. The World Food Programme confirmed unauthorised access to its…

June 2026 Patch Tuesday covers 110 approved patch records and 392 unique CVEs across Microsoft, Adobe and SAP.

Apple extended Private Cloud Compute onto Google Cloud and NVIDIA hardware, turning attestation, independent roots of trust and public verification into the privacy boundary.

France says one hijacked Tchap account exposed public-room content associated with 73,467 officials. Private encrypted histories were not reported compromised.