Security Roundup: Tata/Apple/Tesla Breach, Klue OAuth Supply Chain, Cisco UCM Webshells, Lantronix ICS Zero-Day, Atomic Arch AUR — Week of June 26, 2026
Weekly briefing: 630GB Apple/Tesla trade secrets leaked, Klue OAuth Salesforce data theft, Cisco UCM webshells, and Atomic Arch.
A week defined by the largest confirmed Apple and Tesla supply chain data breach to date, a cascading OAuth supply chain attack draining Salesforce CRM data from hundreds of companies including leading security firms, Cisco's voice infrastructure actively exploited with Tor-routed webshells achieving root, a critical OT/ICS code injection flaw with a same-day federal patching deadline, and a sophisticated Linux supply chain campaign deploying eBPF rootkits through 1,500+ Arch Linux packages. Here is everything you need to know and act on.
1. Tata Electronics Breach — 630 GB of Apple and Tesla Trade Secrets Leaked (World Leaks Ransomware)
Tata Electronics — a Tier-1 hardware supplier to Apple and Tesla — confirmed a major cybersecurity incident on June 22, 2026, after the World Leaks ransomware extortion group published more than 630 GB of stolen data comprising 204,300+ files on a dark web forum.
A sample review by TechCrunch confirmed Apple component supplier specifications, Tesla manufacturing documents including drawings for an upgraded Model Y chargeport controller ("NV36 Chargeport Controller – North America"), and a 2023 Tesla Project Highland (revamped Model 3) file marked "TRADE SECRET." Employee passport copies, internal emails, and multi-year event logs were also included. Apple confirmed it is investigating the incident and a ransom demand has been made. No CVE — initial access vector has not been publicly disclosed by Tata Electronics.
Significance: This incident illustrates the systemic IP exposure created by Tier-1 hardware supply chain integration. OEM-level trade secrets are stored by suppliers with far less security maturity than the OEMs themselves, creating leverage for ransomware extortion against the ultimate customer.
Action: Apple and Tesla suppliers should audit what IP is stored with manufacturing partners. OEMs should evaluate zero-trust data sharing portals and supplier breach notification clauses.
2. Klue/Salesforce OAuth Breach — Icarus Steals CRM Data from Hundreds of Orgs via Stale Integration Credential
Market intelligence platform Klue was breached on June 11, 2026 through a stale, never-revoked service credential created for a prototype integration that was later abandoned. The threat group Icarus used that credential to pivot into Klue's integration infrastructure, harvest OAuth tokens connecting Klue to customer Salesforce orgs, then queried those Salesforce environments directly to exfiltrate CRM data.
Icarus claimed the attack on June 19. Confirmed victims include: Huntress, Recorded Future, Tanium, Jamf, Sprout Social, Gong, HackerOne, OneTrust, and Insurity — with The Register reporting "hundreds" of affected Klue customers total. Salesforce has disabled the Klue Battlecards integration. Data stolen includes customer names, email addresses, sales notes, CRM records, pricing, and internal sales communications.
Root cause: Abandoned integration credential with persistent OAuth scope access. This pattern is endemic across SaaS ecosystems.
Action: Audit all OAuth apps connected to your Salesforce org (Setup → Connected Apps OAuth Usage). Revoke anything inactive. Implement integration lifecycle policies that trigger credential revocation on decommission. Expect targeted phishing against contacts from stolen CRM data.
3. CVE-2026-20230 — Cisco Unified CM SSRF → Root: Tor-Routed Webshells Confirmed as of June 24
CVE-2026-20230 (CVSS 8.6) is an unauthenticated SSRF in Cisco Unified Communications Manager's WebDialer service. Cisco patched it on June 3, a public PoC dropped on June 5, and active exploitation with automated Tor-routed three-stage JSP webshell drops was confirmed by June 24, 2026 — a 19-day window from patch to mass exploitation.
Attack chain: Unauthenticated HTTP request to WebDialer → SSRF to write malicious file to OS path → Stage 1 JSP loader deployed → Stage 2 payload fetched from C2 → Stage 3 shell with root-level access. Attackers are routing exploitation through Tor exit nodes, making IP-based blocking ineffective. Patching alone does not evict a dropped webshell — compromise assessment is required if you were unpatched after June 3.
Action: Patch immediately. If WebDialer is not operationally required, disable it — this eliminates the attack surface entirely. Audit for JSP files in non-standard directories. Restrict network access to Unified CM management interfaces.
4. CVE-2025-67038 — Lantronix EDS5000 CVSS 9.8 Code Injection: CISA KEV, Federal Deadline June 26 (Today)
CVE-2025-67038 (CVSS 9.8) is an unauthenticated OS command injection in the Lantronix EDS5000 Series — serial-to-Ethernet converters widely deployed in ICS, OT, and industrial automation environments. The HTTP RPC module concatenates an unsanitized username parameter directly into a shell command, enabling root-level code execution with no authentication required. CISA added it to the KEV catalog on June 23, 2026, with a federal FCEB agency remediation deadline of June 26, 2026 (today).
OT/ICS significance: EDS5000 devices act as Ethernet bridges for serial-connected PLCs, RTUs, sensors, and industrial controllers. Compromising one can give attackers direct command access to otherwise air-gapped control network equipment. The fix is available: upgrade to EDS5000 firmware 2.2.0.0R1.
Action: Patch immediately. Ensure EDS5000 management interfaces are behind firewall ACLs. Search Shodan for product:"Lantronix EDS5000" to verify your exposure.
5. Atomic Arch — 1,500+ AUR Packages Backdoored with eBPF Rootkit and Credential Harvester
The Atomic Arch supply chain campaign began June 11, 2026 and compromised over 1,500 Arch User Repository (AUR) packages by exploiting AUR's orphan-adoption mechanism. Attackers requested ownership of abandoned-but-reputable packages, then modified PKGBUILD files and install hooks to pull malicious npm packages (atomic-lockfile, js-digest) during installation. A second wave on June 12 used Bun-based install paths.
The final payload is an eBPF rootkit with kernel-level persistence, process/file/network hiding, debugger detection, and exfiltration of: SSH keys, HashiCorp Vault tokens, browser cookies, collaboration app tokens (Slack, Discord), CI/CD environment variables, .env files, and AWS/GCP/Azure credentials. All data is uploaded via HTTPS to attacker infrastructure.
Action: Any system that installed an AUR package between June 11 and present should be treated as potentially compromised. Rotate all credentials. Run the community detection script (lenucksi/aur-malware-check). Review PKGBUILD diffs before installing any AUR packages going forward.
Deep Dives
For full technical analysis, attack chain breakdowns, IOCs, and remediation commands, see the individual deep-dive posts:
- Tata Electronics Breach: 630 GB of Apple and Tesla Trade Secrets Leaked by World Leaks
- Klue OAuth Breach: Icarus Steals Salesforce CRM Data from Huntress, Tanium, Recorded Future and Hundreds More
- CVE-2026-20230: Cisco Unified CM SSRF → Root — Tor-Routed Webshell Drops Confirmed, Patch Now
- CVE-2025-67038: Lantronix EDS5000 CVSS 9.8 Code Injection — CISA KEV, ICS/OT Alert, Federal Deadline Today
- Atomic Arch: 1,500+ AUR Packages Backdoored with eBPF Rootkit and Credential Harvester