LastPass confirms data theft after Klue supply chain attack

LastPass has disclosed that customer data was exposed in a cyberattack targeting Klue, a third-party platform integrated with its Salesforce environment, rather than LastPass’s own systems. The attackers reportedly exploited stolen OAuth tokens to access CRM data, exposing customer names, contact information, support case details, and sales records, but not password vaults, master passwords, or encrypted user data. LastPass said it quickly responded by revoking Klue access, rotating compromised API tokens, investigating the incident with Klue and Salesforce, and notifying law enforcement. The breach also affected several other cybersecurity companies, highlighting the growing risks of supply chain attacks and the abuse of third-party SaaS integrations. Although users’ password vaults remain secure, LastPass is advising customers to stay alert for phishing and social engineering attempts that may use the stolen contact information.

Read more about it here.

Microsoft Releases Record-Breaking Patch Tuesday: 208 CVEs

Microsoft Patch Tuesday security updates for June 2026 broke a record: Microsoft provided fixes for 208 CVEs across Windows OS, Microsoft Office, Azure cloud services, Exchange Server, Hyper-V, Secure Boot, BitLocker, and a range of AI tools. If we add Chromium and third-party components bundled in Microsoft products, the total reaches 571 CVEs for the month. At least two CVEs are exploited in the wild.

The record-breaking volume of patches signals a significant increase in vulnerability discovery rates across Microsoft’s product ecosystem.

Read more about it here.

DentaQuest data leak exposes 2.6 million patients

The ShinyHunters extortion group has published a 234 GB archive of data allegedly stolen from dental benefits administrator DentaQuest. The cybergang added the company to its Tor data leak site in May 2026, and the data was released after negotiations failed. The breach could affect approximately 2.6 million individuals whose information may have been exposed.

DentaQuest acknowledged the data breach and quickly moved to contain the attack. It said its systems remain operational with minimal disruption. Technical details about the security breach haven’t been disclosed yet.

According to data breach notification service HaveIBeenPwned, the leaked data includes 2.6 million email addresses, names, phone numbers, addresses, dates of birth, and healthcare-related records, some containing Medicaid IDs.

DentaQuest is the second largest dental benefits administrators in the US and a subsidiary of Sun Life US. The company manages dental and vision benefits for over 32 million Americans, with a strong focus on Medicaid, CHIP, Medicare Advantage, and commercial plans. It operates more than 70 dental practices.

Read more about it here.