惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hugging Face - Blog
Hugging Face - Blog
云风的 BLOG
云风的 BLOG
大猫的无限游戏
大猫的无限游戏
M
MIT News - Artificial intelligence
L
LangChain Blog
阮一峰的网络日志
阮一峰的网络日志
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Recent Announcements
Recent Announcements
IT之家
IT之家
Google DeepMind News
Google DeepMind News
罗磊的独立博客
爱范儿
爱范儿
Last Week in AI
Last Week in AI
人人都是产品经理
人人都是产品经理
U
Unit 42
MongoDB | Blog
MongoDB | Blog
S
SegmentFault 最新的问题
B
Blog
博客园 - 叶小钗
月光博客
月光博客
Stack Overflow Blog
Stack Overflow Blog
V
Visual Studio Blog
C
Check Point Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知

Android Authority

I know YouTube Music is flawed, yet I prefer it over Spotify Survey reveals 50% of users don’t like the new Google Health app It’s time for Samsung’s S Pen to evolve or die The Motorola Moto G Stylus (2026) is a sequel we didn’t need NotebookLM is quickly becoming the podcast app I didn’t know I needed Samsung’s next Galaxy Watch update could finally make your health data useful Google’s Gemini Spark is ready to run your digital errands while your phone is off Telegram’s finally getting an official Wear OS app again Nintendo is back on mobile, and it wants to turn your selfies into minigames Google Drive’s big document scanner overhaul is finally here — don’t overlook its power Spotify will finally give you real profile tools to make music listening more social Acer’s new gaming handheld might dodge the worst of tech inflation Meta is cooking up a new line of smart glasses, and they may not be Ray-Bans ChatGPT is retiring this beloved legacy model in June Is Microsoft Copilot not working? Here’s what’s going on (Update: Back up) Samsung Gallery starts quietly ending OneDrive support ahead of schedule Here’s a first look at custom wallpapers in Google Messages Rivian is pretty sure customers want AI, not Android Auto Leaked iPhone 18 Pro dummy units may have just shown the next Android phone color trend A company spent $500 million in one month after forgetting to set AI usage limits Now even MediaTek’s cheap chips are embarrassing the Tensor G5 in one major area Pixel 10 Pro XL user says Google returned their phone worse than dead The best robot pool cleaners of 2026: Top picks for all budgets and pool sizes Claude Opus 4.8 is more honest, less deceptive, and considerably cheaper Roborock’s Qrevo Curv 2 Flow is ready to mop up the competition — and your filthy floors Google is making it easier to share Gemini chats, media, and more with your team One UI 9 borrows one of the iPhone’s most useful call features This is the biggest mistake Oura is making with the Oura Ring 5 This Verizon user owed $400, but the carrier made an unexpected move Google’s Fitbit Air makes a strong case for minimalism and ditching your smartwatch
Another LastPass security breach traces back to a comprom...
Jay Bonggolto · 2026-06-24 · via Android Authority
LastPass alternatives Free vs Premium photograph

Joe Hindy / Android Authority

TL;DR

  • LastPass suffered another data incident, but this time the breach originated from third-party vendor Klue rather than LastPass itself.
  • Hackers stole OAuth tokens from Klue, giving them access to connected Salesforce and Gong environments used by LastPass.
  • Exposed information includes customer names, contact details, support case records, physical addresses, and some sales data.

LastPass is dealing with yet another security incident, but this time, the company says the problem came from one of its vendors, rather than the infamous breaches it has suffered in the past.

The company has confirmed in a blog post that hackers accessed some customer information after compromising Klue, a third-party competitive intelligence platform used by LastPass’ go-to-market teams. LastPass said it first became aware of the incident on June 12. In an investigation, it was found that attackers gained access to OAuth tokens stored by Klue, which gave them access to connected services used by several customers, including LastPass. The compromised integrations linked Klue to Salesforce and Gong environments used by LastPass.

The exposed details include customer names, email addresses, phone numbers, physical addresses, support case records, and some sales-related data. LastPass stressed that its own infrastructure wasn’t breached and that password vaults, encrypted credentials, and core services remained untouched.

Separately, Klue said the attackers accessed the system using a compromised legacy credential associated with an integration tool. Once inside, threat actors were able to steal customer OAuth tokens and use those tokens to extract data from connected cloud platforms. Since then, the company has revoked affected credentials, disabled several integrations, and removed the malicious access from its systems.

Salesforce’s security team also had to step in after seeing suspicious activity and disabled Klue’s app connection. The CRM giant said the problem was with the third-party app and not due to a vulnerability in Salesforce itself.

For LastPass users, the company says no action is required to protect stored passwords because vault data was not involved. However, affected customers should be more vigilant. Attackers can use contact information and support tickets to launch phishing attempts and social engineering campaigns.

Thank you for being part of our community. Read our Comment Policy before posting.