
Work Here?
Company Historically Provides H1B Sponsorship
Splunk analyzes large sets of machine data from IT systems, IoT devices, and security tools to provide real-time insights through its Data to Everything platform. It collects, searches, analyzes, and visualizes data so teams can monitor infrastructure, detect issues, and make informed decisions quickly. It differentiates itself by ingesting diverse data sources across IT, security, and business analytics, offering cross-domain visibility and security insights at scale, with integrations to technologies like Palo Alto Networks and Cisco. Its goal is to help organizations improve operational efficiency and security posture by turning data into actionable insights.
Industries
Data & Analytics
Enterprise Software
Cybersecurity
Company Size
5,001-10,000
Company Stage
IPO
Headquarters
San Francisco, California
Founded
2003
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$2.7B
Above
Industry Average
Funded Over
9 Rounds
Medical, dental and vision insurance plans for regular, full-time U.S. employees — choose the best plans for you and your family. Plus: Health Savings Account (HSA), Life insurance and survivor benefits, Flexible Spending Accounts (FSA), Business travel and accident insurance, Voluntary Critical Illness & Hospital Indemnity
Eligible employees enjoy: 401(k) Plan with a company match, Employee Stock Purchase Plan (ESPP), Equity awards, Bonus or commission program
We support you and your family: Paid parental leave, Mother rooms and wellness rooms, Family Planning
Your work/life balance is important to us, that's why we offer: 16 company holidays, 15 vacation days, 10 sick days, 10 bereavement days, 5 volunteer days
Ensuring our employees' success goes beyond insurance plans: Education reimbursement, Electric car charging stations, Employee Assistance Program (EAP), Stocked kitchens, Gym discounts/onsite fitness centers, Pet insurance discount, Student loan resources, Cool workspace with collaborative environments, 529 College Savings Plan
Safetech Innovations accelerates in H1 2026: consolidated net profit increases by 53% to RON 8.5 million. Safetech Innovations (BVB: SAFE), a Romanian cybersecurity company listed on the Bucharest Stock Exchange, with offices in Bucharest, London, Abu Dhabi and Riyadh, reports, at consolidated level, a turnover of RON 25.7 million in the first half of 2026, up 34% compared to the same period last year, an operating profit of RON 10.4 million, up 52%, and a net profit of RON 8.5 million, representing a 53% increase compared to H1 2025. "The results recorded in the first half of the year confirm Safetech Innovations' return to a solid growth trajectory, in a context in which cybersecurity is becoming increasingly important for both public and private-sector organizations. Over the past years, we have built a company capable of combining technical expertise, recurring services and proprietary solutions with access to highly complex projects. This positioning gives us confidence in Safetech's ability to capitalize on the opportunities available both in Romania and on international markets and to continue creating long-term value for our clients and shareholders," stated Victor Gânsac, Chairman of the Board of Directors of Safetech Innovations. At individual level, Safetech Innovations' turnover amounted to RON 25.2 million in the first six months of 2026, up 36% compared to the same period of the previous year. Recurring cybersecurity services and security solution implementation projects contributed approximately equally to turnover, accounting for around 50% each. Individual operating profit reached RON 10.4 million, up 44%, while individual net profit amounted to RON 8.6 million, 42% above the level recorded in H1 2025. "The performance recorded in the first half of the year demonstrates that we can sustain an accelerated pace of growth while maintaining an efficient operating structure. The fact that we achieved this level of performance with a team that increased by only two employees compared to H1 2025 reflects the progress made in terms of productivity and resource utilization. The integration of artificial intelligence-based tools into our day-to-day operations is also contributing to greater workflow efficiency. In the period ahead, we will focus on implementing the projects we have secured and delivering them to the quality standards that have supported Safetech's development and our long-term relationships with clients," stated Ionuț Georgescu, CEO of Safetech Innovations. In terms of Safetech UK, the entity generated revenues of approximately RON 974 thousand, up 30% compared to the same period last year, and attracted four new clients, primarily for cybersecurity services. At the same time, the subsidiary's operating costs decreased by 12%, while its loss for the first half of the year narrowed to approximately RON 13 thousand. A project initially scheduled for this period was postponed to the third quarter, and the company expects Safetech UK to become profitable in Q3 2026. The European business continued to develop, supported by projects carried out under the European Commission's FREIA (Fortified Security, Resilience, Expertise, Intelligence and Adaptability) framework agreement and by strategic partnerships with major international integrators. These collaborations facilitate Safetech Innovations' participation in more complex projects and contribute to the gradual increase in the share of international contracts in the company's revenues. The positive commercial momentum continued both during the reporting period and after its end. In May and July, Safetech Innovations signed two significant contracts, each with a duration of 36 months, worth RON 4.34 million and EUR 2.7 million, respectively, excluding VAT, for the provision of cybersecurity services and solutions. The company also entered into a 48-month framework agreement with the Authority for the Digitalization of Romania for the provision of cybersecurity assessment services required for the migration of certain applications to the Government Private Cloud. For the second half of 2026, Safetech Innovations' management expects the favorable trend observed in the first six months of the year to continue, supported by the current project portfolio, ongoing recurring contracts and opportunities generated by the company's international operations. Safetech Innovations has been listed on the Main Market of the Bucharest Stock Exchange since February 6, 2023, and is traded under the symbol SAFE. About Safetech Innovations Since 2011, Safetech Innovations S.A. has been providing customized cybersecurity services and solutions tailored to the needs of each organization. The company's portfolio of services and solutions includes consulting for governance, risk management, and compliance (GRC) in security, security testing and vulnerability management, security solutions, professional services, outsourced security services, and proprietary software applications for cybersecurity. Safetech Innovations has established partnerships with several leading cybersecurity companies, such as CheckPoint, DarkTrace, Microsoft, Splunk, Fidelis, HID, Cynet, and Phriendly Phishing. Currently employing over 60 staff members, the company has dedicated teams to research and develop cybersecurity software products, implement and support security solutions, and Computer Emergency Response Team (CERT) services. The company serves clients from various sectors, including utilities, healthcare, insurance, industrial manufacturing, retail, and the public sector. Additionally, seven of the top ten banks in Romania have chosen Safetech as their cybersecurity service provider. Safetech Innovations has been involved in over a hundred projects to secure critical infrastructures in the United States, Canada, Brazil, Morocco, the European Union, Singapore, the Philippines, India, China, and New Zealand. Safetech Innovations (SAFE) is listed on the Main Market of the Bucharest Stock Exchange as of February 6, 2023. More information about Safetech Innovations is available at www.safetech.ro
ReliaQuest: how ReliaQuest stopped a ShinyHunters breach attempt. ReliaQuest Thwarts ShinyHunters Social Engineering Attack Targeting Okta SSO On 23 August 2026, cybersecurity firm ReliaQuest confirmed a social engineering attack linked to the ShinyHunters threat group, which attempted to breach its systems using a fake Okta Single Sign-On (SSO) page. The attackers, posing as IT support, tricked an employee into approving a multi-factor authentication (MFA) push during an impersonation call, granting them access to a view-only identity dashboard session. The breach was contained quickly due to ReliaQuest's layered security controls, including device-trust policies that restricted the attacker to a single session. No business applications, customer data, or company data were accessed, and no persistence was established. The compromised credentials were immediately expired and reset upon detection. The attack followed a well-documented playbook: threat actors registered a lookalike domain, hosted a fake SSO page behind a content delivery network (CDN), and used phone-based impersonation to deceive the employee. The incident mirrored a recently disclosed WordPress plugin flaw that allowed authentication bypass, reinforcing the need for defense-in-depth strategies rather than reliance on single security measures. ReliaQuest's GreyMatter platform, which integrates with Splunk, CrowdStrike, Fortinet, and Google Cloud Chronicle, played a key role in normalizing telemetry data and enabling rapid response. The company emphasized that phishing remains effective, particularly when attackers leverage employee names and urgency to manipulate victims. A week prior, ReliaQuest's threat research team had shared intelligence on ShinyHunters, highlighting the group's use of fake domains and MFA bypass techniques. The screenshots of the compromised Okta dashboard, initially posted on X (formerly Twitter), were later deleted. The incident underscores the growing sophistication of social engineering attacks, even against cybersecurity providers. "id": "REL1787660926", "linkid": "reliaquest", "type": "Cyber Attack", "date": "8/2026", "severity": "25", "impact": "1", "explanation": "Attack without any consequences" {'affected_entities': [{'customers_affected': 'None', 'industry': 'Cybersecurity', 'name': 'ReliaQuest', 'type': 'Cybersecurity Firm'}], 'attack_vector': 'Fake Okta SSO page, MFA push manipulation, phone-based ' 'impersonation', 'data_breach': {'data_exfiltration': 'No', 'personally_identifiable_information': 'No', 'type_of_data_compromised': 'None'}, 'date_detected': '2026-08-23', 'date_publicly_disclosed': '2026-08-23', 'date_resolved': '2026-08-23', 'description': 'On 23 August 2026, cybersecurity firm ReliaQuest confirmed a ' 'social engineering attack linked to the ShinyHunters threat ' 'group, which attempted to breach its systems using a fake ' 'Okta Single Sign-On (SSO) page. The attackers, posing as IT ' 'support, tricked an employee into approving a multi-factor ' 'authentication (MFA) push during an impersonation call, ' 'granting them access to a view-only identity dashboard ' 'session. The breach was contained quickly due to ReliaQuest's ' 'layered security controls, including device-trust policies ' 'that restricted the attacker to a single session. No business ' 'applications, customer data, or company data were accessed, ' 'and no persistence was established. The compromised ' 'credentials were immediately expired and reset upon ' 'detection.', 'impact': {'data_compromised': 'None', 'operational_impact': 'Minimal (contained quickly)', 'systems_affected': 'Okta identity dashboard (view-only session)'}, 'initial_access_broker': {'backdoors_established': 'No', 'entry_point': 'Fake Okta SSO page, lookalike ' 'domain'}, 'investigation_status': 'Contained and resolved', 'lessons_learned': 'The incident underscores the growing sophistication of ' 'social engineering attacks, even against cybersecurity ' 'providers. Defense-in-depth strategies are critical, and ' 'phishing remains effective when attackers leverage ' 'employee names and urgency.', 'post_incident_analysis': {'corrective_actions': 'Credential reset, ' 'device-trust policies ' 'enforcement, enhanced ' 'monitoring', 'root_causes': 'Social engineering (MFA push ' 'manipulation), fake Okta SSO page, ' 'phone-based impersonation'}, 'recommendations': 'Implement layered security controls, enforce device-trust ' 'policies, and educate employees on social engineering ' 'tactics.', 'references': [{'source': 'ReliaQuest Threat Research Team'}, {'source': 'X (formerly Twitter)'}], 'response': {'containment_measures': 'Device-trust policies, credential ' 'expiration and reset', 'enhanced_monitoring': 'GreyMatter platform integration with ' 'Splunk, CrowdStrike, Fortinet, and ' 'Google Cloud Chronicle', 'incident_response_plan_activated': 'Yes', 'remediation_measures': 'Compromised credentials expired and ' 'reset'}, 'threat_actor': 'ShinyHunters', 'title': 'ReliaQuest Thwarts ShinyHunters Social Engineering Attack Targeting ' 'Okta SSO', 'type': 'Social Engineering', 'vulnerability_exploited': 'Human vulnerability (social engineering), ' 'potential WordPress plugin flaw (authentication ' 'bypass)'} Published by Cybersecurity Gaps Expose Australia's Transport and Logistics Sector Australia's transport and logistics industry a critical backbone for supply... Aug 25, 2026 Sotheby's International Investigates Cybersecurity Incident Involving Client Data Luxury real estate firm Sotheby's International is probing a cybersecurity... Aug 25, 2026 Historic McQuay Farmhouse Preserved Amid Charlotte's Growth; Preferred Parking Reports Data Breach Charlotte's Historic McQuay Farmhouse Stands as... Aug 24, 2026
Atlassian, Splunk patch 250+ critical and high vulnerabilities. Atlassian and Splunk released patches this week for more than 250 vulnerabilities; Atlassian fixed 10 critical and 162 high-severity issues while Splunk addressed at least 150 flaws. Atlassian and Splunk released security updates this week that address more than 250 vulnerabilities across multiple products. Atlassian's bulletin, published Tuesday, lists fixes for 10 critical and 162 high-severity issues tied to third-party libraries used in Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible and Jira. The fixes cover roughly 109 unique CVEs. The bulletin warns that successful exploitation of some defects could allow remote code execution, denial-of-service, information theft, man-in-the-middle attacks, authentication bypass and server-side request forgery. On Wednesday Splunk published updates for Splunk Enterprise, SOAR, Universal Forwarder and related apps and add-ons. Enterprise versions 10.4.2, 10.2.6, 10.0.9 and 9.4.14 address 60 vulnerabilities, including three rated critical. Splunk also patched at least two dozen security defects in third-party packages bundled with Enterprise. Several Splunk Apps and Add-ons, including AI Toolkit, Connect for Kafka, MCP Server app and On-Call, received updates for critical and high-severity bugs. Multiple dependency issues in SOAR were corrected. Splunk released Enterprise Security 8.6.1 to fix two high-severity issues, updated SOAR Connectors to resolve 17 medium- and low-severity flaws, and issued a Universal Forwarder update that addresses three medium-severity OpenSSL weaknesses. Both vendors report that many defects stem from shared libraries embedded across products, so a single vulnerable dependency can affect multiple applications. That pattern accounts for many CVEs being addressed at once. Atlassian's bulletin lists affected product versions and the patched library versions. Splunk's release notes and product pages list version numbers and mitigation details for each update. Administrators are advised to consult the vendor notices to determine which releases to install. Industry tracking shows an increase in large, multi-product patch releases in recent months as vendors update embedded third-party components.
Splunk fixes 17 vulnerabilities including critical MCP Server RCE. August 20, 2026 Splunk has released a security hardening update addressing 17 vulnerabilities across several applications and add-ons, including a critical remote code execution (RCE) flaw in the Splunk MCP Server app. Security consulting services Discover more Cyberattack prevention software Computer Security The vulnerabilities encompass deserialization, access control, server-side request forgery (SSRF), denial-of-service, certificate validation, and information disclosure. Tracked as SVD-2026-0808 and published on August 19, 2026, the advisory affects the following products: Cisco Talos Intelligence for Enterprise Security Cloud, Splunk AI Toolkit, Splunk Connect for Kafka, Splunk MCP Server, and Splunk On-Call (VictorOps). The most severe issue, identified as CVE-2026-76404, received a CVSS v3.1 score of 9.1. Critical MCP Server RCE. CVE-2026-76404 is an unsafe deserialization vulnerability in the Splunk MCP Server app. An authenticated attacker with high privileges could exploit this flaw remotely to execute arbitrary code within the affected environment. The vulnerability is classified as CWE-502, or deserialization of untrusted data. Its CVSS vector indicates network reachability, low attack complexity, no user interaction required, and a high impact on confidentiality, integrity, and availability. Although elevation of privileges is necessary, successful exploitation could enable a highly privileged user or a compromised administrative account to execute code within the Splunk deployment. Discover more Ethical hacking course Exploit mitigation solutions Vulnerability scanning tool Splunk has addressed this issue in version 1.2.1 of the MCP Server app. Organizations using versions before 1.2 are advised to upgrade immediately and review privileged account activity, MCP Server access logs, and application logs for any signs of anomalous deserialization or execution behavior. The Splunk AI Toolkit accounts for 10 out of the 17 disclosed vulnerabilities. The most serious CVE-2026-76395 is another unsafe deserialization flaw in the Model Loading REST API, rated 8.8. A low-privilege authenticated attacker could execute arbitrary code via a malicious model-loading request. Other high-severity vulnerabilities in the AI Toolkit include improper privilege management, missing authorization in container and connection management, insecure access controls for experiment history, and risky permissions for scheduled searches. Hacking & Cracking Given the volume and variety of these flaws, the AI Toolkit is a priority for administrators, particularly when integrated with containerized services, model repositories, scheduled searches, or shared Splunk roles. Splunk has issued fixes in version 6.0.1 for the 6.0 branch and version 6.0.0 for the 5.7 branch. Splunk Connect for Kafka contains four vulnerabilities, led by CVE-2026-76402, an unauthenticated SSRF issue rated 8.2. An attacker could potentially exploit the REST API to make requests from the affected server to internal or otherwise restricted network resources. Additional fixes have been issued for improper certificate validation in the HTTP Event Collector's Kerberos authentication, a denial-of-service condition in the REST API, and a regular expression denial-of-service vulnerability. Administrators are encouraged to upgrade to version 2.2.7. Discover more Security consulting services Data Management Threat intelligence reports Cisco Talos Intelligence for Enterprise Security Cloud is impacted by a high-severity SSRF vulnerability (CVE-2026-76389) and a medium-severity information disclosure issue (CVE-2026-76390). Both of these vulnerabilities have been resolved in version 1.0.3. CVE details. Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world. Hot this week
Splunk patches critical MCP Server RCE and 16 other security flaws across AI Toolkit, Kafka apps. 2026-08-20 12:08 Splunk has released security updates for 17 vulnerabilities affecting several apps and add-ons, including Splunk MCP Server, Splunk AI Toolkit, and Splunk Connect for Kafka. The most severe issue, tracked as CVE-2026-76404, is a critical remote code execution vulnerability with a CVSS score of 9.1. The advisory, published on August 19, 2026, also covers Cisco [...] Read the original article: Splunk has released security updates addressing multiple vulnerabilities across Splunk Enterprise, Splunk Cloud Platform, and the Splunk AI Toolkit that could lead to denial-of-service (DoS) conditions and exposure of sensitive data. The issues, disclosed on May 20, 2026, include three tracked vulnerabilities: CVE-2026-20238, CVE-2026-20239, and CVE-2026-20240. Splunk AI Toolkit Access... Online security courses May 22, 2026 In "Cyber Security News" Splunk has released security updates addressing multiple vulnerabilities across Splunk Enterprise, Splunk Cloud Platform, and the Splunk AI Toolkit that could lead to denial-of-service (DoS) conditions and exposure of sensitive data. The issues, disclosed on May 20, 2026, include three tracked vulnerabilities: CVE-2026-20238, CVE-2026-20239, and CVE-2026-20240. Splunk AI Toolkit Access... May 22, 2026 In "Cyber Security News" Splunk has released security updates to fix three newly disclosed vulnerabilities that could allow low-privileged users to access sensitive data or disrupt Splunk Enterprise deployments through denial-of-service (DoS) conditions. The patches address issues in both Splunk Enterprise and the Splunk Cloud Platform, as well as the Splunk AI Toolkit app... May 22, 2026
Find jobs on Simplify and start your career today
Industries
Data & Analytics
Enterprise Software
Cybersecurity
Company Size
5,001-10,000
Company Stage
IPO
Headquarters
San Francisco, California
Founded
2003
Find jobs on Simplify and start your career today