HP Research: Who Has the Remote? Attackers Are Turning Legitimate Remote Access Tools Into Backdoors HP

Splunk Enterprise Pre-Auth RCE Chain Exposes Database With Zero Authentication
A critical vulnerability chain in Splunk Enterprise has been disclosed, enabling unauthenticated attackers to achieve remote code execution (RCE) through a misconfigured PostgreSQL sidecar service.


