authorization

AppWizard
June 30, 2026
Jennifer Gibbons, Vice President of State Government Affairs at the Entertainment Software Association (ESA), stated during a California State Senate hearing that community servers for Minecraft and Call of Duty are "illegal" and equate to "piracy." She mentioned that the ESA has pending lawsuits against private servers and that the United States Trade Representative (USTR) has identified some private servers as notorious markets for piracy. Gibbons' comments were challenged by Assemblyman Chris Ward, who noted the existence of community servers for both games. An ESA representative later clarified that Gibbons was responding to a complex question and that private servers hosting copyrighted content without authorization infringe on the intellectual property rights of game publishers. The ESA reported a total revenue of ,614,556 in the fiscal year ending March 2025, with ,804,681 from member dues.
AppWizard
June 30, 2026
The California State Senate hearing on the Protect Our Games Act raised questions about the legality of private Minecraft servers. Assemblyman Chris Ward noted that games like Minecraft and Call of Duty have successfully used community servers, while Jennifer Gibbons from the ESA argued that these servers are illegal and unapproved by Microsoft, labeling them as piracy. Gibbons stated that the ESA has two lawsuits against private servers for infringing on intellectual property rights. In contrast, Minecraft's official stance encourages the creation of third-party servers, which are vetted for compliance with community standards. The ESA maintains that private servers infringe on publishers' rights. The USTR's Notorious Market Report referenced by Gibbons does not specifically target community servers for connecting friends but focuses on those bypassing subscription services. The Protect Our Games Act did not advance but will be reconsidered. An ESA representative later clarified that private servers hosting copyrighted content without authorization infringe on publishers' rights and highlighted concerns about safety standards on these platforms.
Tech Optimizer
June 23, 2026
A critical security vulnerability, SVD-2026-0603 (CVE-2026-20253), has been identified in Splunk Enterprise versions 10.0.0 through 10.0.6 and 10.2.0 through 10.2.3. This flaw allows unauthenticated, remote attackers to create or truncate arbitrary files on the host system by exploiting the PostgreSQL Sidecar Service endpoints. The vulnerability is actively exploited, with public proof-of-concept code available, and has been added to the CISA Known Exploited Vulnerabilities (KEV) list. Successful exploitation can lead to full remote code execution (RCE) as the Splunk user. The vulnerability arises from inadequate authentication controls on the PostgreSQL Sidecar Service endpoints, specifically /v1/postgres/recovery/backup and /v1/postgres/recovery/restore, which are accessible without authentication. It is classified under CWE-306: Missing Authentication for Critical Function and has a CVSS v3.1 base score of 9.8 (Critical). Attackers can exploit the vulnerability by sending crafted HTTP POST requests to the exposed endpoints, allowing them to create or truncate files and potentially execute malicious scripts. Indicators of compromise include unexpected files in directories such as /tmp/ or /opt/splunk/var/run/supervisor/pkg-run/, modified Splunk Python scripts, and unusual outbound connections from Splunk to unknown PostgreSQL servers. The vulnerability aligns with several MITRE ATT&CK techniques, including T1190 (Exploit Public-Facing Application) and T1059 (Command and Scripting Interpreter). Active exploitation of CVE-2026-20253 has been confirmed, and it is likely that both opportunistic cybercriminals and sophisticated threat actors will use this exploit. The affected versions of Splunk Enterprise are 10.2.0 through 10.2.3 and 10.0.0 through 10.0.6, with the issue resolved in versions 10.2.4 and 10.0.7. Organizations are advised to upgrade to fixed versions or disable the PostgreSQL Sidecar Service as a mitigation strategy.
Tech Optimizer
June 13, 2026
On June 10th, Splunk released an advisory for CVE-2026-20253, a high-severity vulnerability with a CVSS score of 9.8 that requires no authentication. The vulnerability is associated with the PostgreSQL Sidecar Service Endpoint and affects Splunk Enterprise versions 10 and above. In default installations, the service is not installed on Windows but is installed and enabled by default on AWS. The vulnerability allows unauthorized users to create and truncate arbitrary files through an API that lacks authentication controls. Additionally, it enables the execution of SQL commands via a backup and restore mechanism, potentially leading to remote code execution (RCE). A Detection Artefact Generator has been developed to help organizations assess their vulnerability to this issue.
Search