# Threat Intel Brief — June 15, 2026

TL;DR

  • Critical RCE vulnerabilities in Splunk Enterprise (CVE-2026-20253) and Oracle PeopleSoft (actively exploited) require immediate patching to prevent unauthenticated remote code execution.
  • Chinese state-sponsored APT maintained covert access to authentication infrastructure for approximately 10 years, achieving full visibility into isolated network operations.
  • FBI disrupted Outsider Enterprise, a Chinese phishing-as-a-service platform operating thousands of AI-powered credential harvesting sites targeting financial services.
  • U.S. government ordered Anthropic to suspend foreign national access to advanced AI models Claude Fable 5 and Mythos 5, signaling expansion of export controls into the AI domain.
  • Insider threat prosecution resulted in 21-month sentence for former school IT employee who conducted prolonged cyberattack against Iowa district.

Critical Threats

Splunk Enterprise Unauthenticated RCE (CVE-2026-20253)

What happened: Splunk released security updates addressing a critical vulnerability (CVE-2026-20253) in Splunk Enterprise versions below 10.2.4 and 10.0.7. The flaw allows unauthenticated attackers to perform arbitrary file operations and achieve remote code execution with a CVSS score of 9.8.

Impact: Splunk Enterprise serves as the backbone for security monitoring and log aggregation in enterprise environments worldwide. Successful exploitation grants attackers complete system control over Splunk infrastructure, enabling exfiltration of sensitive security logs, establishment of persistence mechanisms, and potential lateral movement into monitored networks. Organizations relying on Splunk for security operations face severe risk if instances are internet-facing or accessible from untrusted networks. While no active exploitation has been publicly reported, the critical severity and unauthenticated attack vector make exploitation highly likely once technical details become public.

Recommendations:

  • Immediately upgrade Splunk Enterprise to version 10.2.4, 10.0.7, or later depending on your major version branch
  • Audit network exposure of all Splunk Enterprise instances and restrict access to trusted management networks only
  • Review Splunk access logs (splunkd_access.log and audit.log) for suspicious unauthenticated requests or unusual file operations prior to patching
  • If immediate patching is not feasible, implement strict firewall rules or WAF policies to block unauthenticated access to Splunk web interfaces
  • Verify that Splunk instances are not directly exposed to the internet; use VPN or jump hosts for administrative access

Oracle PeopleSoft RCE — Active Exploitation

What happened: CERT.BE issued a critical warning regarding an actively exploited remote code execution vulnerability in Oracle PeopleSoft. Threat actors are targeting vulnerable PeopleSoft deployments in the wild. Specific CVE: see source.

Impact: Critical risk for organizations running PeopleSoft, particularly internet-facing instances. Successful exploitation enables full system compromise via remote code execution. Attackers can gain unauthorized access to sensitive HR, financial, and enterprise data stored in PeopleSoft systems. The active exploitation status indicates immediate threat to unpatched systems. PeopleSoft deployments are prevalent across European enterprises and public sector entities, making this a high-priority concern for organizations in finance, human resources, and government sectors.

Recommendations:

  • Identify all Oracle PeopleSoft instances in your environment, prioritizing internet-facing systems
  • Apply Oracle Critical Patch Update immediately — check Oracle support portal for latest PeopleSoft security patches
  • If patching cannot be completed within 24 hours, isolate PeopleSoft systems from internet access via firewall rules or WAF
  • Monitor PeopleSoft access logs and web server logs for suspicious POST requests, unusual authentication attempts, or unexpected code execution
  • Review recent PeopleSoft system activity for indicators of compromise, including unauthorized user accounts, file modifications, or data exfiltration

Chinese APT — Decade-Long Authentication Infrastructure Compromise

What happened: Chinese state-sponsored hackers compromised an organization's authentication infrastructure and maintained persistent access for approximately 10 years, achieving full visibility into administrative activities on an isolated network.

Impact: This operation demonstrates exceptional sophistication and patience characteristic of advanced Chinese APT groups. The compromise of authentication systems enabled complete visibility into administrative activities across network boundaries, including isolated or air-gapped environments. The decade-long dwell time suggests the target held sustained strategic value for Chinese intelligence objectives, likely involving intellectual property theft, strategic reconnaissance, or pre-positioning for future operations. Organizations with isolated networks containing sensitive data or critical systems face similar risks from well-resourced state actors.

Recommendations:

  • Implement robust authentication monitoring with behavioral analytics to detect anomalous administrative account usage patterns, including unusual login times, source IPs, and privilege escalation activities
  • Deploy multi-factor authentication (MFA) with hardware tokens or FIDO2 keys for all administrative accounts, particularly those with access to authentication infrastructure and isolated networks
  • Conduct regular authentication infrastructure audits to identify unauthorized modifications to authentication processes, including backdoored authentication modules, rogue accounts, or modified access control lists
  • Implement network segmentation monitoring and anomaly detection to identify unauthorized traffic between isolated networks and enterprise environments
  • Perform comprehensive credential rotation and authentication infrastructure rebuilds when long-term compromise is suspected, as credential dumping may have exposed all historical authentication secrets

Threat Actor Activity

Outsider Enterprise — Chinese Phishing-as-a-Service Disrupted

The FBI, in coordination with Google and Black Lotus Labs, disrupted Outsider Enterprise, a Chinese phishing-as-a-service operation that operated thousands of phishing websites designed to harvest credit card data and passwords. The platform leveraged AI-powered techniques to enhance the effectiveness and scale of phishing campaigns, offering phishing capabilities as a commercial service to other cybercriminals.

Targeting: The operation primarily targeted the financial services sector and the general public, maximizing victim pool size for credential and payment card theft. The phishing-as-a-service model enabled less sophisticated actors to conduct credential harvesting at scale.

Defensive measures: Organizations should monitor for phishing indicators including suspicious domain registrations mimicking legitimate financial services brands. Implement email security controls with AI-powered phishing detection, deploy multi-factor authentication across all user accounts, and conduct user awareness training focused on identifying AI-enhanced phishing techniques. Establish threat intelligence sharing with industry ISACs and law enforcement to receive indicators of compromise related to known PhaaS infrastructure.

Chinese State-Sponsored APT — Long-Term Persistence Operations

Chinese state-sponsored hackers demonstrated advanced tradecraft in maintaining covert access to authentication infrastructure for approximately one decade. The operational profile—extended persistence, authentication infrastructure compromise, and focus on administrative visibility—aligns with known Chinese APT tradecraft documented by Western intelligence agencies. The targeting of isolated networks reflects an evolution in Chinese APT operations, moving beyond standard enterprise networks to more secure, segmented environments that typically house sensitive data or critical systems.

Geopolitical Context

U.S. Expands Export Controls to Advanced AI Models

The U.S. government ordered Anthropic to suspend access to its advanced AI models Claude Fable 5 and Mythos 5 for foreign nationals, citing national security concerns. Anthropic complied with the directive but disputed the government's technical rationale, arguing the cited vulnerability is narrow and similar capabilities exist elsewhere. The directive represents an expansion of U.S. export control philosophy into the AI domain, treating advanced language models as dual-use technologies with strategic implications.

Implications: The move signals that Washington now views certain AI systems as falling within the same export control framework traditionally applied to semiconductors and encryption. While no specific state actors are named, the nationality-based restriction framework is consistent with existing U.S. export control regimes targeting China, Russia, and other strategic competitors. The policy may accelerate efforts by the European Union and other partners to develop sovereign AI capabilities, reducing dependence on U.S. providers. The precedent may prompt other AI labs to implement preemptive geographic or nationality-based restrictions, fragmenting the global AI ecosystem along geopolitical lines.

Chinese Cyber Operations Continue Across Multiple Domains

The disruption of Outsider Enterprise and disclosure of the decade-long APT compromise highlight the breadth of Chinese cyber operations, spanning both financially motivated cybercrime and state-directed espionage. While Outsider Enterprise appears to be a profit-driven operation, its operation from or links to China raises questions about the permissive environment for cybercriminal infrastructure in certain jurisdictions. The APT compromise reflects strategic intelligence collection consistent with China's documented cyber espionage priorities in support of national strategic objectives, including economic competitiveness and technological advancement.

Recommended Actions

Immediate (0-24 hours)

  • Patch Splunk Enterprise to version 10.2.4 or 10.0.7+ to address CVE-2026-20253
  • Patch Oracle PeopleSoft systems immediately; isolate from internet if patching cannot be completed within 24 hours
  • Audit network exposure of Splunk and PeopleSoft instances; restrict access to trusted networks only
  • Review authentication logs for anomalous administrative activity, particularly on isolated or high-security networks

Near-term (24-72 hours)

  • Conduct authentication infrastructure audit to identify unauthorized modifications, rogue accounts, or suspicious access patterns
  • Deploy MFA with hardware tokens for all administrative accounts, prioritizing authentication infrastructure and isolated network access
  • Review PeopleSoft and Splunk access logs for indicators of compromise prior to patching
  • Implement email security controls with AI-powered phishing detection to counter evolving PhaaS threats

This week

  • Assess AI model access controls if your organization uses advanced AI systems; prepare for potential nationality-based restrictions
  • Conduct insider threat assessment focusing on privileged access management and monitoring for critical systems
  • Establish threat intelligence sharing with industry ISACs and law enforcement for PhaaS infrastructure indicators
  • Review network segmentation and monitoring between isolated networks and enterprise environments
  • Implement behavioral analytics for authentication monitoring to detect long-term persistent access patterns

Watch List

  • Oracle PeopleSoft exploitation activity: Monitor for additional technical details, CVE assignment, and indicators of compromise as threat intelligence emerges
  • Splunk Enterprise CVE-2026-20253: Watch for public proof-of-concept exploits or active exploitation reports
  • U.S. AI export control expansion: Monitor for additional directives affecting other AI providers or models; assess impact on research and commercial operations
  • Chinese APT authentication compromise TTPs: Watch for technical indicators and detection guidance from cybersecurity vendors
  • Phishing-as-a-service evolution: Monitor for successor platforms to Outsider Enterprise and continued AI-powered phishing technique development

Sources

  • BleepingComputer: FBI disrupts massive AI-powered phishing service using a million URLs
  • BleepingComputer: Ex-school district employee jailed for hacks on former employer
  • BleepingComputer: Chinese hackers hijack auth flow, spy on isolated network for a decade
  • BleepingComputer: US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos
  • The Hacker News: Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication
  • The Hacker News: U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals
  • CERT.BE (Belgium): Warning: Critical, Actively exploited RCE in Oracle PeopleSoft, Patch Immediately!