Top stories.
- LastPass says Klue breach affected customer information, but passwords remain secure.
- Attackers begin exploiting Cisco Unified CM vulnerability.
- Alleged criminal marketplace administrator extradited to the US.
LastPass says Klue breach affected customer information, but passwords remain secure.
Password manager provider LastPass has disclosed that the Klue supply-chain attack breached personal information and customer support case records belonging to LastPass customers, TechCrunch reports. The company stressed that "LastPass products, services, and infrastructure were not impacted in any way and customer vaults remain secure." The breach involved business contact information from the company's Salesforce environment, including customer names, phone numbers, email addresses, physical addresses, and support case information.
Meanwhile, Klue has shared additional details surrounding the breach, during which attackers stole OAuth tokens and gained access to a number of Klue's corporate customers. Klue stated, "Our investigation determined that an attacker gained access through a compromised legacy credential associated with an integration service. The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments." A Klue spokesperson told TechCrunch that the compromised legacy credential "was originally provided to a third-party in 2022, for a limited pilot."
Attackers begin exploiting Cisco Unified CM vulnerability.
Attackers are now exploiting a high-severity flaw in Cisco Unified Communications Manager Server that was patched on June 3rd, BleepingComputer reports. The vulnerability (CVE-2026-20230) can "allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device," and later use this access to elevate privileges to root.
Threat intelligence company Defused said in an X post yesterday, "Over the weekend we observed exploitation of CVE-2026-20230 - Cisco Unified CM (CUCM) WebDialer SSRF → root file-write (CVSS 8.6). No previously recorded exploitation, and not yet listed in CISA KEV. This is currently being exploited from a single source using an unvetted PoC, with genuinely-formatted file:// file-write payloads landing on our decoys."
Alleged criminal marketplace administrator extradited to the US.
An Algerian national who was arrested in Spain has been extradited to the US to face charges related to his alleged operation of two cybercriminal marketplaces, SecurityWeek reports. 26-year-old Abdellah Belmili is accused of running the Market0Day and Spoxy criminal markets, as well as developing phishing kits that targeted major American banks.
The US Justice Department said in a press release, "During the course of the conspiracy, Belmili is accused of defrauding multiple institutions, including American Express, Bank of America, JP Morgan Chase, and Wells Fargo, as well as financial institutions in the United Kingdom. Between January 2020 and January 2023, approximately $900,000 was deposited into an account controlled by Belmili. The investigation has also identified approximately 5,600 U.S. and international victims."
Belmili is facing a maximum of 30 years in prison for conspiracy to commit bank fraud.
Business news: Accenture acquires Dragos, runZero, and NetRise for more than $4 billion.
Accenture has acquired a majority stake in Maryland-headquartered OT security firm Dragos and fully acquired exposure management company runZero and software supply chain security provider NetRise (both based in Austin, Texas) for a combined value of approximately $4.175 billion. NetRise and runZero will be integrated into Dragos's platform. Accenture stated, "The Dragos Platform will expand to cover the extended environment that controls physical processes, while Accenture's deep OT security expertise, unique industrial datasets, and decades of trusted relationships with critical infrastructure operators will address a need previously unaddressed at scale." Dragos will continue to operate as an independent business, with co-founder Robert M. Lee remaining as CEO.
Read more in the Business Briefing at 4pm ET.