Dossier
Splunk
Coverage of Splunk in the Nexus archive.
- Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication
Splunk has released security updates to address a critical flaw in Splunk Enterprise, allowing unauthenticated users to perform file operations and execute remote code. The vulnerability, CVE-2026-20253, has a CVSS score of 9.8 and affects versions below 10.2.4 and 10.0.7.
- Singapore boffins get diverse SIEMs singing in harmony with agentic rule translation
Researchers from National University of Singapore and Fudan University developed a technique called ARuleCon to translate rules from diverse Security Information and Event Managements (SIEMs) for easier consumption across multiple systems. This technique enables the translation of SIEM rules created using various platforms, including Splunk, Microsoft Sentinel, and IBM QRadar. The goal is to make AI useful for cyber-defenders.