KDDI disclosed that attackers reached an email system shared across six Japanese ISPs by exploiting a third-party software flaw spotted on June 17. Up to 14.2 million logins may have been taken, though many passwords were stored hashed or encrypted; the firm has notified regulators and partner providers while urging password resets.

KDDI noted that many credentials existed only in hashed or encrypted states, reducing the chance they could be used right away to seize accounts.
The company urges anyone who might be affected to change their email password at once and to activate two-factor authentication wherever the option exists.
Tap a lens to see what this story means for you.
Reader-supported · Daily Brief
Daily brief at 7 AM ET. Top tech stories, every morning. Sourced and fact-checked.
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
NHTSA has closed its investigation into power steering loss on 376,241 Tesla Model 3 and Model Y vehicles after Tesla deployed an over-the-air software fix. The closure marks another regulatory win for the company even as a separate FSD visibility probe remains active.
Tata Electronics confirmed a cybersecurity incident after extortion group World Leaks published more than 630 GB of data that is overwhelmingly Apple-related according to a file index. The breach affects an Indian contract manufacturer that assembles iPhones and supplies other global tech companies.
The Linux Foundation launched Akrites on Thursday with 19 founding members including major tech firms and banks to organize remediation of critical open source vulnerabilities before AI-powered attackers can exploit them. The project tackles the reality that fewer than 5% of thousands of AI-identified flaws have received patches by instituting one confidential response team in place of scattered reports.