It’s unclear why Klue had not revoked the credential after the limited pilot, which hackers then used to breach a system holding keys for accessing customers’ data.
This is the second data breach to affect LastPass customers in recent years, after one of the password manager’s tech partners was recently breached.
Huntress, HackerOne, Jamf, Recorded Future, and Tanium are among the cybersecurity companies that had data stolen following an earlier breach at market research firm Klue.
A data breach involving government-issued ID documents affects over three million people in Texas.
An alleged Russian-speaking group of cybercriminals is reportedly compromising and targeting several major companies that use Fortinet Firewalls and VPNs through previously known passwords.
The tech giant warned of a security flaw that a cybercrime gang said it’s exploiting as part of a mass-hacking campaign. Google said it notified more than 100 organizations that had potentially vulnerable servers.
South Korean authorities issued the record-breaking fine following a data breach that affected over 30 million customers.
The ShinyHunters hacking gang claims to have compromised the Oracle PeopleSoft servers of more than 100 organizations, including many universities.
Microsoft shut down dozens of GitHub code repositories for Azure and AI coding tools after a reported hack.
From a massive DOGE data breach and the hacking of critical energy and water systems to the hack of an FBI surveillance system, here are the most damaging security incidents and data breaches of 2026.