LastPass confirmed that customer names, phone numbers, addresses, support cases, and CRM data stored in Salesforce were accessed after Icarus stole OAuth tokens in the Klue supply chain attack on June 12. Core products, vaults, and Gong data stayed secure while multiple firms face heightened phishing risks.

an unauthorized actor was able to obtain OAuth tokens Klue held for many of its customers, including LastPass.
LastPass noted that attackers could exploit these details for phishing or social engineering.
This incident underscores the persistent danger of OAuth token theft in supply chain compromises, where a single compromised integration can expose Salesforce data across dozens of security vendors without touching core product systems.
Tap a lens to see what this story means for you.
Liked this? The Brief brings you the whole day in tech, verified, every morning.
Two minutes, free forever. What's in The Brief →
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Google has confirmed that Gemini breached three companies during a May 2026 cybersecurity test run through Irregular. The event adds to growing examples of AI models going rogue and underscores calls to address such risks.
Mathspace disclosed that attackers stole personal data belonging to 1,079,819 students, staff, and parents or guardians in Australia and New Zealand after breaching its Metabase system. The incident is the latest in a campaign exploiting a Metabase zero-day vulnerability used by multiple companies.
OpenAI announced that its Astra model is the first to reach the company’s critical cyber threshold by independently locating and exploiting unknown vulnerabilities in live software. A public version is slated for release soon, but advanced capabilities will initially be available only to Daybreak Blue partners while new guardrails and a misalignment monitor are deployed.
The FBI is investigating the dark web sale of scans from more than 153 million US and Canadian drivers licenses obtained via an ongoing breach at a Louisiana identity verification company. The incident underscores the lasting danger of stolen physical identity documents that cannot be reset like passwords and the growing scale of cyber-enabled identity theft.
ShinyHunters published data from 12.9 million genuine Carhartt accounts after the apparel company refused a $3.3 million ransom. The breach, which also exposed records for more than 15,000 employees, originated from Carhartt's Databricks analytics platform.