infosecfollow

daily plain-text briefing: security, markets, business, and pittsburgh

Splunk patched a 9.8-severity hole that hands unauthenticated attackers code execution on the monitoring platform security teams lean on, the freshest danger on a day filled with AI-governance fights and self-inflicted data leaks.


Security

Vulnerabilities and Exploits

1. Splunk Enterprise Pre-Auth Code Execution Flaw

[patch, rce]

Latest developments: Splunk shipped patches for CVE-2026-20253, a 9.8-severity flaw that lets an unauthenticated attacker create or truncate arbitrary files and run code on Splunk Enterprise.

read more

The bug hits Splunk Enterprise versions below 10.2.4 and 10.0.7, where an unauthenticated user performs arbitrary file operations that escalate to remote code execution. Splunk runs at the heart of many security operations centers, so a compromise hands attackers the monitoring platform itself. Administrators should upgrade to 10.2.4 or 10.0.7 at once and lock down management-interface exposure.

Sources: The Hacker News

Data Breaches

2. Hack Cover-Up Claims Hit IBM and AT&T

[breach, policy]

Latest developments: SecurityWeek reported accusations that IBM and AT&T concealed past hacks from the public, alongside news that Google cut staff from its security organization.

read more

The roundup surfaces claims that IBM and AT&T hid security incidents from customers and regulators, conduct that breach-notification laws penalize. Google laid off members of its security team even as attack surfaces widen. The same dispatch flagged flat industrial-control-system exposure and a fresh Microsoft incident-response playbook for AI.

Sources: SecurityWeek

3. Argentina World Cup Squad Passport Leak

[breach, privacy]

Latest developments: A botched document redaction exposed the passport numbers of Lionel Messi and the rest of Argentina's World Cup squad before the tournament kicked off.

read more

Someone published a team document without properly redacting it, spilling players' passport details to anyone who looked. No hacker touched the file; the leak came from ordinary human error, a recurring source of data exposure. The episode shows how a redaction slip exposes sensitive identity data as reliably as any breach.

Sources: Graham Cluley

Policy and Regulation

4. Sanders Floats an AI Sovereign Wealth Fund

[policy, ai]

Latest developments: Senator Bernie Sanders, in a New York Times essay, proposed an AI sovereign wealth fund and warned that a handful of billionaires steer artificial intelligence with little democratic input.

read more

Sanders argues that the people building and profiting from AI wield power that escapes public accountability, and he wants a sovereign-wealth structure to spread the gains. Security commentator Bruce Schneier amplified the question through the lens of his book on rewiring democracy. The proposal widens a policy fight over who governs AI, days after Washington forced Anthropic to pull two models over export concerns.

Sources: Schneier on Security

Threat Detection and Forensics

5. New MacOS Tahoe Forensic Artifact

[forensics, macos]

Latest developments: Palo Alto's Unit 42 disclosed a previously unknown macOS Tahoe 26 artifact that records a user's menu selections across the operating system.

read more

The artifact logs which menu items a user picks system-wide, giving investigators a fresh timeline of on-device activity. Forensic analysts and incident responders can mine it to reconstruct what someone actually did on a Mac. Defenders gain a new evidence source, and the same trail could expose user behavior in ways privacy-minded owners never anticipate.

Sources: Unit 42 (Palo Alto)

Business and Politics

Pittsburgh

Weather

Today: Chance Showers And Thunderstorms, high 84F.

Tonight: Showers And Thunderstorms then Mostly Cloudy, low 56F.

Monday: Mostly Sunny, high 71F.

Business

Around Town

Events

Sports

Pirates (36-35)

Sat Jun 13 · Marlins 2 · Pirates 3 · Final

Spencer Horwitz hit by pitch with the bases loaded to lift the Pirates past the Marlins, 3-2

Up Next · Marlins @ Pirates · Sun Jun 14, 12:15 PM

Reading

Markets

weekly average, change vs prior week

S&P 500     7,377.03  ▼ -2.2%
Dow        50,725.58  ▼ -0.7%
Nasdaq     25,695.30  ▼ -3.8%
WTI crude      88.42  ▼ -5.0%
EUR/USD       1.1550  ▼ -0.4%
GBP/USD       1.3363  ▼ -0.6%
USD/JPY       160.31  ▲ +0.3%