Splunk is a technology platform tracked across 22 threat clusters and 24 intelligence report mentions on ThreatCluster. First observed November 10, 2025; most recent activity July 16, 2026.
Splunk is a data analytics platform that indexes, searches, and analyzes machine data from IT, security, and business sources. Frequently deployed as a SIEM and security analytics solution (Splunk Enterprise Security, Splunk Cloud), it converts raw telemetry into dashboards, alerts, and automated workflows to support threat detection and incident response. Its ability to ingest vast volumes of logs, events, and metrics makes it significant for cybersecurity operations across enterprises and MSSPs.
Two significant vulnerabilities have been identified in the Splunk AI Toolkit versions below 5.7.4. The first, CVE-2026-20265, allows low-privileged users to exfiltrate data by making unauthorized HTTP requests to…
A critical security advisory has been issued regarding a high-severity vulnerability in Splunk, tracked as CVE-2026-20163, published on 2026-03-11. This flaw affects both Splunk Enterprise and Cloud platforms, allowing…
Splunk has issued security updates for three vulnerabilities in Splunk Enterprise and Splunk Cloud Platform. These vulnerabilities, tracked as CVE-2026-20296, CVE-2026-20297, and CVE-2026-20298, were disclosed on July…
A critical vulnerability (CVE-2026-20251) has been identified in Splunk Enterprise, Splunk Cloud Platform, and Splunk Secure Gateway, allowing low-privileged users to execute remote code. This vulnerability arises from…
The Mistic malware, a newly identified Windows backdoor, has been active since April 2026, utilizing DLL sideloading to infiltrate enterprise environments. It exploits a legitimate executable, MpExtMs.exe, to load a…
Splunk has issued security updates for vulnerabilities in Splunk Enterprise, Splunk Cloud Platform, and the Splunk AI Toolkit that could result in denial-of-service (DoS) attacks and sensitive data exposure. The…
CrowdStrike announced new AI security features at RSA 2026, focusing on endpoint protection as AI applications proliferate. The Falcon platform now includes EDR AI Runtime Protection, which monitors commands and…
A series of vulnerabilities in Fluent Bit, an open source log collection tool, were discovered by Oligo Security. These 'trivial-to-exploit' bugs, which allow attackers to bypass authentication and execute remote code,…
Trend Micro has introduced advanced AI-driven solutions like Agentic SIEM and XDR to enhance cybersecurity. These systems aim to improve threat detection and response by breaking down silos in security operations.…
On May 11, 2026, Oracle published guidance on enhancing cybersecurity for its ERP and HCM applications. The focus is on securing sensitive transactions involving AI agents, service accounts, and various users. The…