Broken digital shields representing widespread system compromises.

Daily Cybersecurity News - June 13, 2026

Critical Splunk Flaw Lets Attackers Run Code

Splunk Enterprise has a critical unauthenticated flaw that hands attackers remote code execution.

CVE-2026-20253 scores CVSS 9.8. It lets unauthenticated users perform file operations that lead straight to code execution on the server.

Affects Splunk Enterprise deployments running vulnerable versions. Self-hosted instances without network restrictions are directly exposed.

WatchTowr published a technical breakdown two days after the June 10 advisory. No confirmed in-the-wild exploitation yet.

Chinese hackers hijack auth flow spy on isolated network for a decade

Chinese state hackers took over a target organization's authentication stack and kept full access for ten years.

They hijacked the auth flow itself to monitor every admin action with almost no on-disk artifacts. The victim appears to be an isolated network in a high-value sector.

This is classic China-aligned tradecraft with one twist: persistence through the identity layer rather than standard implants. Most groups still rely on scheduled tasks or services.

The same cluster has maintained similar access in other targets since at least 2016.

Over 400 Arch Linux Packages Compromised

Attackers compromised more than 400 packages in the Arch User Repository to push a Linux rootkit and infostealer.

They targeted credentials and access tokens on developer machines. The malware spreads through seemingly legitimate AUR packages that users install for work.

This is a supply-chain hit on a popular distro's community repo. Attackers reused the tactic of poisoning package metadata rather than building novel code.

A handful of attacker-controlled accounts adopted 400+ orphaned packages through AUR's ownership-transfer process, then rewrote their build scripts.

ShinyHunters Uses Oracle Zero Day to Rampage Higher Ed

ShinyHunters hit dozens of universities by exploiting a zero-day in Oracle PeopleSoft.

They chained unauthenticated remote code execution in the Environment Management component with MeshCentral agents disguised as cloud endpoints. Targets skewed heavily toward US higher education between May 27 and June 9.

The group usually relies on vishing for SaaS access. This time they shifted to a direct unauthenticated exploit against exposed ERP instances.

Mandiant notified over 100 organizations, with 68 percent in higher education.

Source: Dark Reading