The Lyceum: Cyber Intelligence Daily — Jun 24, 2026
Photo: lyceumnews.com
Wednesday, June 24, 2026
Morning Command Brief
- Disable Cisco WebDialer now: CVE-2026-20230 in Unified Communications Manager is under active exploitation, letting an unauthenticated attacker write files to disk via SSRF and escalate to root.
- Patch UniFi OS by Friday: three CVSS 10.0 flaws (CVE-2026-34908/-34909/-34910) chain into unauthenticated root RCE across nearly 100,000 internet-exposed endpoints, with a June 26 CISA KEV deadline.
- Rotate Japanese ISP email credentials: KDDI's breach of a shared email platform exposed up to 14.2 million accounts across six ISPs, with email content possibly compromised and a June 25 Nifty deadline.
What Changed Overnight
Cisco Unified CM Actively Scanned — Disable WebDialer Immediately
SecurityWeek confirmed June 24 that CVE-2026-20230 (CVSS 8.6, Critical rating) has moved from public PoC to in-the-wild exploitation; Defused observed a single IP using file:// payloads to write files to the OS. Any enterprise running Unified CM for call routing, voicemail, and click-to-dial is exposed to unauthenticated root compromise. Patch to 14SU6 (v14) or the interim COP patch (v15); if you can't patch, disable the Cisco WebDialer Web Service in Unified Serviceability for a zero-downtime mitigation. Current activity looks like reconnaissance — the window to act is hours, not days.
Three UniFi OS CVSS 10.0 Flaws Hit CISA KEV — Friday Deadline
CISA added CVE-2026-34908, -34909, and -34910 with a June 26 deadline; researchers confirmed an improper access control flaw, path traversal, and command injection chain into unauthenticated root RCE on the UniFi OS Server. Bishop Fox validated the full path on a live instance and published a detection script; Censys tracks nearly 100,000 exposed endpoints, mostly U.S. Fix is UniFi OS Server 5.0.8+. This is the same vendor whose routers Russia's GRU abused via the Moobot botnet the FBI dismantled in February 2024 — both state and criminal actors know this hardware.
KDDI Shared Email Breach — 14.2M Accounts, Six ISPs
KDDI detected unauthorized access on June 17 to an email platform it manages for itself and other Japanese ISPs, storing data on up to 14.2 million users; attackers exploited a vulnerability in third-party software, and email content may have been compromised. The platform also serves STNet, JCOM, Chubu Telecommunications, Nifty, and BIGLOBE. Anyone using @nifty, BIGLOBE, or JCOM email should change passwords now — Nifty invalidates exposed credentials at June 25, 23:59 JST.
LastPass Confirms Data Stolen via Klue Supply Chain
Per BleepingComputer, LastPass confirmed attackers reached its Salesforce data after stealing OAuth tokens in the Klue compromise. The Icarus group breached Klue on June 12 using a compromised legacy integration credential to obtain OAuth tokens connecting Klue to customers' Salesforce instances. Accessed data likely includes account metadata and support records; LastPass has not confirmed whether vault data was involved — and that distinction is everything. The recurring vector is a forgotten third-party integration credential, not a broken password.
Coverage Notes
- Coverage note: CVE-2026-21509: Actively Exploited Microsoft Office Zero-Day Forces Emergency Patch — This is a required major-headline item for reader awareness; monitor vendor guidance, exploitation reports, and any emergency patch timeline. Key terms: Microsoft Office, zero-day, actively exploited, emergency patch, CVE-2026-21509. Source: SOC Prime.
Watch Next
- If GreyNoise telemetry on Cisco Unified CM port 8443 spikes in the next 48 hours, it means the reconnaissance phase has ended and webshell drops are next — patch ahead of compromise immediately.
- If LastPass confirms vault-adjacent data was accessed via Klue, it means this stops being a CRM incident and every shared-vault customer should rotate privileged credentials.
- If the UniFi KEV deadline passes with significant exposure still on Censys, it means the unauthenticated root chain will land in commodity exploit kits within a week, and 100,000 endpoints become an open opportunistic target.