~/greenteam/nerd

Sunday, June 14, 2026

Daily digest

cybersec The Hacker News

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

Splunk has patched CVE-2026-20253, a CVSS 9.8 vulnerability in Splunk Enterprise versions below 10.2.4 and 10.0.7. An unauthenticated attacker can exploit the flaw to create or truncate arbitrary files and achieve remote code execution. Updates are available now.

Why it matters: If Splunk is part of your SIEM or log aggregation pipeline — including in a CMMC L2 audit trail context — unpatched instances are exposed to unauthenticated RCE. Verify your deployed version and patch immediately; NIST 800-171 SI.3.218 requires timely remediation of critical vulnerabilities.

cybersec BleepingComputer

Chinese hackers hijack auth flow, spy on isolated network for a decade

A Chinese threat actor compromised a target organization's authentication infrastructure and maintained undetected persistence for approximately ten years, gaining full visibility into administrative activity on an air-gapped or isolated network. The attackers manipulated the authentication flow rather than relying on conventional malware footholds. Details of the specific techniques involved are documented in a new threat report.

Why it matters: This attack pattern — owning the auth stack rather than individual endpoints — is directly relevant to environments relying on identity as a security boundary, including Intune/Entra ID and GCC High tenants. Review conditional access policies, authentication logs, and privileged identity protections; ten-year dwell time indicates detection gaps that CMMC AC and IA control families are specifically designed to close.

cybersec BleepingComputer

US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos

The U.S. government ordered Anthropic to block all foreign nationals from accessing its Fable 5 and Mythos 5 AI models, citing national security concerns related to a jailbreak capability. Anthropic complied by suspending both models globally, while publicly disputing the breadth of the order and characterizing the cited risk as narrow. The export control action forced worldwide service disruption.

Why it matters: If your self-hosted or externally accessed AI stack incorporates Anthropic models via API, those specific models are now unavailable. More broadly, this signals that export control mechanisms are actively being applied to frontier AI models — a compliance dimension to track if your organization uses or plans to procure commercial AI services in a CUI-adjacent context.

cmmc NextGov

Anthropic suspends top AI models after U.S. export control order

Following a U.S. government export control order, Anthropic disabled its Fable 5 and Mythos 5 models for all customers worldwide, not just foreign nationals. The government cited national security concerns as the basis for the restriction. Nextgov's reporting covers the government-side context and policy rationale behind the order.

infrastructure The Register

AWS rolls the dice for faster, more efficient networking

AWS has announced a significant redesign of its datacenter network architecture aimed at reducing latency and improving throughput efficiency across its cloud infrastructure. The approach flattens traditional network hierarchy within AWS facilities. The change is intended to benefit workloads sensitive to east-west traffic latency.

Why it matters: Architectural networking improvements at AWS can translate to measurable latency and throughput gains for workloads running in AWS GovCloud; worth monitoring whether similar changes roll out to the GovCloud regions and whether any network path changes affect existing security group or traffic inspection configurations.

cybersec BleepingComputer

Ex-school district employee jailed for hacks on former employer

A former IT employee of an Iowa school district was sentenced to 21 months in federal prison for conducting a sustained cyberattack against his former employer after leaving the organization. The attacks disrupted classroom operations, deleted user accounts, and caused tens of thousands of dollars in damages. The case proceeded to criminal sentencing rather than civil action.

Why it matters: This is a textbook insider threat and offboarding failure case. For a CMMC L2 environment, it reinforces the criticality of PS.2.127 (termination procedures) and AC controls — verify that account deprovisioning workflows in Intune/Entra ID fully revoke access at separation, with no residual credentials or VPN tokens remaining active.