Cybersecurity Daily: News & Threats · 20 Jun 2026 · 4 min

Splunk RCE Exploited & Icarus OAuth Attack Hit CRM Data

A critical Splunk Enterprise RCE (CVE-2026-20253, CVSS 9.8) is under active attack with a federal patch deadline of June 21, while threat actor Icarus stole OAuth tokens from SaaS vendor Klue to silently extract CRM data from Huntress, Jamf, Recorded Future, and Tanium. Two stories, one pattern: attackers reaching infrastructure that was never designed to stop them.

Cybersecurity Daily: News & Threats
Now Playing
Splunk RCE Exploited & Icarus OAuth Attack Hit CRM Data

Audio is available on Spreaker — see link below.

What's covered

Splunk RCE Under Active Attack

A critical Splunk Enterprise vulnerability is now confirmed under active exploitation, and federal agencies have until June twenty-first to patch it. That deadline isn't arbitrary.

Listen now →

CVE-2026-20253 Exploit Chain

The vulnerability tracked as CVE-2026-20253 carries a CVSS score of nine-point-eight. Unauthenticated remote code execution in Splunk Enterprise versions ten-point-zero-point-six and ten-point-two-point-three.

Listen now →

Klue OAuth Token Compromise

Simultaneously, a separate incident is revealing a different kind of structural weakness. A threat actor tracked as Icarus stole OAuth tokens from Klue, a competitive intelligence SaaS vendor.

Listen now →

Why OAuth Tokens Bypass Defenses

The signal here is the monitoring gap. OAuth tokens grant long-lived, passwordless access to third-party platforms.

Listen now →

SaaS Supply Chain Scale

Third-party breaches now account for thirty percent of all breaches, doubled year-over-year. The Klue incident illustrates exactly how that number grows.

Listen now →

What To Watch Now

Two things matter most from here. First, whether organizations running vulnerable Splunk versions can identify undetected compromise before the June twenty-first deadline.

Listen now →

Chapter summary auto-generated from the verified script. Listen to the full episode for the complete content.

More episodes

From Cybersecurity Daily: News & Threats