Key developments
Klue breach exposes LastPass customer data
Klue confirmed attackers breached its integration infrastructure using a compromised legacy credential tied to an integration service, then obtained OAuth tokens for connected platforms including Salesforce. The CyberWire reported that affected organizations include LastPass, Huntress, Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity; All About Cookies reported that LastPass customer vaults were not accessed, but names, phone numbers, email addresses, home addresses, support-case data, and sales CRM records were exposed. The Icarus extortion group claimed responsibility and threatened to leak data unless paid.
Why it matters
A single vendor integration failure exposed customer and CRM data across multiple security and enterprise vendors, increasing phishing and impersonation risk.
Sources & driving stories
THE CYBERWIRE
The CyberWire coverageALL ABOUT COOKIES
All About Cookies coverageMercor breach notifications reveal biometric exposure
Mercor began notifying affected individuals on June 25 and June 26 after a third-party forensic investigation into a March 24–30 supply-chain attack tied to a malicious LiteLLM update. All About Cookies’ Thomas Kent reported that Mercor says only a limited subset of nearly five million experts was affected, while independent reporting and class-action filings allege roughly four terabytes of data stolen and more than 40,000 contractors impacted. Reported exposed materials include passport scans, Social Security numbers, facial biometrics, and video interview recordings, with Lapsus$ allegedly offering the cache on dark web forums.
Why it matters
Biometric and identity-document exposure creates durable privacy harm because victims cannot reset facial data or government identifiers like passwords.
Sources & driving stories
ALL ABOUT COOKIES · Thomas Kent
All About Cookies coverageFBI delays Section 702 abuse records
Yournews reported that a June 5 filing in a Cato Institute FOIA lawsuit says the FBI has 39,650 records that could shed light on alleged FISA abuses, but will not begin releases until Aug. 15. The delay comes as Congress debates renewing Section 702, which allows collection targeting foreigners overseas but can sweep Americans’ communications into searchable databases. The first expected release is only 128 pages, while advocates continue pressing for warrant requirements for searches involving Americans.
Why it matters
Lawmakers may vote on surveillance renewal before the public sees records bearing on FBI compliance and warrantless searches of Americans’ communications.
Sources & driving stories
YOURNEWS
Yournews coverageWorth noting
WORTH NOTING
Xsolis breach hit 1.4M patients
HealthExec reported an HHS filing showing 1,396,519 people affected after a targeted phishing attack exposed protected health information, treatment details, Social Security numbers, and insurance data.
WORTH NOTING
Tata restricts sensitive remote access
Reuters reporting carried by WTVB said Tata Electronics tightened access controls and hired a forensic consultant after World Leaks posted more than 204,000 files totaling over 630 GB, including purported Apple and Tesla design documents.
WORTH NOTING
World Cup scam domains rise
IBTimes reported FortiGuard Labs found more than 13,000 World Cup 2026-themed domains registered from January to May, with 8.8% flagged as malicious and fake ticketing among the highest-risk lures.
Still unclear
OPEN QUESTION
How far does the Klue exposure extend?
Disclosures are still emerging across Klue customers, and the OAuth/Salesforce access path suggests the ultimate affected population may depend on each customer’s connected CRM data.
OPEN QUESTION
Will Congress act before FISA records surface?
The delayed FOIA release could leave lawmakers renewing Section 702 without public access to records about alleged FBI noncompliance and backdoor searches.
