# SANS Stormcast Monday, June 15th, 2026: Arch Linux Malicious User Packages; Splunk Vuln and Exploit; Exploiting AI Coding Agents (#) Page: https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-7764184/sans-stormcast-monday-june-15th-2026-arch-linux-malicious-user-packages-splunk-vuln-and-exploit-exploiting-ai-coding-agents Text version: https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-7764184/sans-stormcast-monday-june-15th-2026-arch-linux-malicious-user-packages-splunk-vuln-and-exploit-exploiting-ai-coding-agents.md Podcast: [SANS Internet Storm Center's Daily Network Security News Podcast](https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-7764184) Published: 2026-06-14T21:24:30+00:00 Episode link: https://mp3.sans.edu/sans-stormcast-monday-june-15th-2026-arch-linux-malicious-user-packages-splunk-vuln-and-exploit-exploiting-ai-coding-agents Audio file: https://traffic.libsyn.com/secure/securitypodcast/9972.mp3?dest-id=448030 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/sans-internet-storm-center-s-daily-network-security-news-podcast-7764184/episodes/sans-stormcast-monday-june-15th-2026-arch-linux-malicious-user-packages-splunk-vuln-and-exploit-exploiting-ai-coding-agents Duration seconds: 410 ## Resource SANS Stormcast Monday, June 15th, 2026: Arch Linux Malicious User Packages; Splunk Vuln and Exploit; Exploiting AI Coding Agents Atomic Arch: Attackers Hijack Trusted AUR Packages to Deliver Rootkit-Like Malware https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/ A Fake Bug Report Hijacks Your AI Coding Agent – and Nothing Catches It. https://tenetsecurity.ai/blog/agentjacking-coding-agents-with-fake-sentry-errors/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: splunk; postgresql; arch linux; atomic arch; arch; ai; agent; ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/sans-internet-storm-center-s-daily-network-security-news-podcast-7764184/episodes/sans-stormcast-monday-june-15th-2026-arch-linux-malicious-user-packages-splunk-vuln-and-exploit-exploiting-ai-coding-agents/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-7764184/sans-stormcast-monday-june-15th-2026-arch-linux-malicious-user-packages-splunk-vuln-and-exploit-exploiting-ai-coding-agents.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.