LastPass confirmed that customer names, phone numbers, addresses, support cases, and CRM data stored in Salesforce were accessed after Icarus stole OAuth tokens in the Klue supply chain attack on June 12. Core products, vaults, and Gong data stayed secure while multiple firms face heightened phishing risks.

an unauthorized actor was able to obtain OAuth tokens Klue held for many of its customers, including LastPass.
LastPass noted that attackers could exploit these details for phishing or social engineering.
This incident underscores the persistent danger of OAuth token theft in supply chain compromises, where a single compromised integration can expose Salesforce data across dozens of security vendors without touching core product systems.
Tap a lens to see what this story means for you.
Reader-supported · Daily Brief
Daily brief at 7 AM ET. Top tech stories, every morning. Sourced and fact-checked.
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
TSMC posted a 77.4% year-on-year profit increase to NT$706.56 billion and raised its capital spending outlook while announcing another $100 billion for Arizona fabs. The results underscore sustained AI demand that now dominates 66% of its platform revenue.
ChangXin Memory Technologies expects to raise 57.9 billion yuan ($8.55 billion) in its Shanghai STAR Market IPO after doubling its original target. The world's fourth-largest DRAM chipmaker will list on July 27, advancing China's push for semiconductor self-reliance.
CISA added CVE-2023-4346 affecting KNX Association KNX Protocol Connection Authorization Option 1 to its Known Exploited Vulnerabilities catalog on 2026-07-15. Federal agencies must finish remediation by 2026-07-29. The overly restrictive account lockout mechanism could let attackers purge devices and set a BCU key when extra security options remain disabled, so organizations must apply vendor mitigations under BOD 26-04.