LodeHQSubscribe →

Splunk pre-auth RCE, OptinMonster 1.2M sites backdoored

Infosec · 2026-06-15

Vulnerabilities & Exploits
Splunk Enterprise on AWS vulnerable to pre‑auth remote code execution by default16 MIN

Splunk Enterprise versions 10+ on AWS ship with an enabled PostgreSQL Sidecar Service that lets unauthenticated attackers execute code remotely (CVE‑2026‑20253, CVSS 9.8). The flaw bypasses the web proxy and hits the sidecar endpoint directly, meaning default cloud deployments are exploitable out of the box. Patch or disable the sidecar to stop pre‑auth RCE.

Supply‑chain breach of OptinMonster injects admin backdoors into 1.2 M WordPress sites5 MIN

Sansec uncovered a supply‑chain attack that hijacked the CDN of Awesome Motive's OptinMonster, TrustPulse and PushEngage plugins, injecting malicious JavaScript that creates hidden admin accounts on 1.2 million WordPress sites. The backdoor activates only for logged‑in admins, giving attackers full control and exposing the broader plugin ecosystem.

SearchLeak enables one-click data siphon from M365 Copilot; Microsoft patches CVE‑2026‑428248 MIN

Varonis Threat Labs discovered SearchLeak, a three‑stage chain in M365 Copilot Enterprise Search that turns a malicious link into a silent data exfiltration tool, stealing emails, files, and calendar items with a single click. Microsoft assigned it CVE‑2026‑42824, rated critical, and has released a patch.

LangGraph’s SQLite checkpointer flaw lets attackers jump from SQL injection to full RCE6 MIN

Check Point Research uncovered three chained flaws in LangGraph's SQLite checkpointer, starting with CVE‑2025‑67644, an SQL injection via a metadata filter. The injection lets an attacker inject malicious SQL that leads to arbitrary deserialization and full remote code execution, jeopardizing any system using LangGraph's persistence layer.

Zero‑day hunter threatens massive Windows exploit dump after Microsoft’s public shaming3 MIN

A disgruntled zero‑day researcher, calling themselves Nightmare, has released six unpatched Windows exploits, three already weaponised, and vowed a "bone‑shattering" dump on July 14. Microsoft responded by involving law enforcement, accusing the researcher of breach of coordination, sparking a rare public feud that could chill future vulnerability disclosures.

Threats & Malware
Malicious ad‑blocker extensions harvest AI chat logs from 90k users4 MIN

Two Chrome extensions posing as ad blockers have been siphoning full chat histories from ChatGPT, Claude, Gemini and five other AI services from roughly 90,000 users. The malicious code captures prompts, responses, model details and subscription status, then exfiltrates the data to operator-controlled servers, revealing a sophisticated data‑theft operation.

FBI, Google bust AI‑powered phishing network that stole 3.8 M cards3 MIN

The FBI, Google and Black Lotus Labs took down Outsider Enterprise, a China‑based AI‑driven phishing‑as‑a‑service that operated over 9,000 fake sites and more than a million URLs, stealing 3.8 million credit cards and causing $1.9 billion in losses. The takedown seized servers, a Shopify store, $100k USDT and a Telegram bot, and Google filed a civil suit to block future scams.

Atomic Arch hijacks AUR packages to drop eBPF rootkit via malicious npm dependency5 MIN

Researchers found the Atomic Arch campaign hijacking abandoned Arch User Repository packages. By swapping PKGBUILDs to pull in the malicious npm module atomic-lockfile, attackers install a Linux payload with eBPF-based rootkit capabilities, potentially affecting up to 1,500 downstream packages. The move shows how supply-chain trust can be subverted without writing new code.

Breaches & Industry News
Tchap breach exposes 73k French civil servants’ data after account hijack2 MIN

France’s official encrypted messaging service Tchap was compromised on June 7, 2026 after a malicious actor hijacked a user account. The breach exposed personal data for 73,467 public‑sector users and gave the attacker access to public‑room messages, underscoring the risk of relying on single‑sign‑on accounts for secure communications.

Privacy, Policy & Governance
US export controls force Anthropic to shut down top cybersecurity AI models4 MIN

Anthropic announced it must abruptly disable its Fable 5 and Mythos 5 models for all users after a U.S. export‑control directive barred foreign nationals from accessing them. The government cited a narrow jailbreak risk, marking the first time export controls target AI models rather than chips, and raising the stakes for AI security tools worldwide.

FCC’s New Rule Would End Anonymous Prepaid Phones, Threatening Privacy1 MIN

The FCC proposal would force carriers to collect government ID and address for every prepaid line, effectively ending burner phones. Advocates warn the blanket data sweep mirrors authoritarian practices and could expose users to surveillance, while the agency claims it’s needed to curb scams.

Research & Tools
North Korean Hackers Hide Recruitment Lures in Google Docs Job Ads7 MIN

A DPRK-linked actor, dubbed FAMOUS CHOLLIMA, posts fake job ads on Google Docs to lure developers into installing credential‑stealing malware. The blog details how to hunt these Docs via urlscan and a custom index, revealing long‑lived accounts and reused assets across campaigns.

Get Infosec in your inbox, every issue.
Subscribe free
Privacy · Terms · About · Contact
© 2026 LodeHQ