LastPass Hit by Another Data Breach as Cybersecurity Threats Mount Globally
Technology

LastPass Hit by Another Data Breach as Cybersecurity Threats Mount Globally

LastPass customers face yet another data compromise while nation-state hackers, infostealer disruptions, and AI security debates dominate this week's cybersecurity landscape.

By Sophia Bennett5 min read

LastPass Customers Hit by Yet Another Data Breach

Password management giant LastPass has found itself at the center of yet another security incident — this time stemming from a breach at a third-party vendor. The company notified customers this week that a compromise at AI business intelligence firm Klue had exposed sensitive customer data, including names, email addresses, phone numbers, physical addresses, and sales and support case information.

Attackers exploited access tokens belonging to Klue's clients — LastPass among them — and leveraged those tokens to extract data from Salesforce and other connected platforms. LastPass was quick to clarify that its own core infrastructure remained intact and that no password vaults were affected.

The company urged its users to stay alert. "We recommend that customers remain vigilant of potential phishing attacks or social engineering attempts, which could leverage exposed contact details," LastPass stated in its official notification. "Always exercise caution regarding unsolicited communications, including emails, phone calls, or requests for sensitive information."

This latest incident adds to a troubling track record of security mishaps for the company, raising ongoing questions about third-party vendor risk management across the tech industry.


John Bolton Pleads Guilty to Mishandling Classified Information

Former national security adviser John Bolton entered a guilty plea on Friday on a single charge related to the illegal retention and mishandling of classified defense materials. The 77-year-old struck a plea agreement that carries a recommended maximum prison sentence of five years, though the deal leaves final sentencing at the discretion of US District Judge Theodore Chuang, who is scheduled to hear the case on October 28.

Under the terms of the agreement, Bolton also consented to paying a $2.25 million fine. However, he retains the right to withdraw his guilty plea should Judge Chuang opt for a harsher penalty or a larger fine than what the deal stipulates. Bolton, who served as a senior adviser during the first Trump administration before becoming one of the president's most vocal critics, now faces the legal consequences of his handling of sensitive government information.


Europol and Microsoft Dismantle Major Infostealer Networks

In a significant blow to the global cybercriminal ecosystem, Europol, Microsoft, and a coalition of international partners announced the successful disruption of infrastructure supporting two widely used infostealers: Amadey and StealC. The coordinated effort formed part of the ongoing Operation Endgame initiative, which targets the tools and platforms that enable ransomware attacks and large-scale cybercrime.

The operation resulted in the seizure and shutdown of 326 servers and 142 domains. Authorities also flagged approximately $47 million in stolen cryptocurrency and recovered up to 27 million compromised access credentials. Microsoft highlighted that AI-assisted analysis played a pivotal role in the operation, revealing that both Amadey and StealC were running on shared backend infrastructure — a discovery that allowed investigators to target them simultaneously and with greater efficiency.


Australia Discovers Nation-State Hackers Embedded in Critical Infrastructure

Australia's Security and Intelligence Organisation (ASIO) has revealed that foreign state-sponsored hackers successfully infiltrated the network of an Australian critical infrastructure provider and were actively preparing for sabotage. The disclosure came alongside the release of ASIO's annual threat assessment.

"ASIO assessed the hackers were preparing for sabotage," said ASIO Director General Mike Burgess. "They were mapping out the network and maintaining access so they could cripple it at a time of their choosing."

Burgess further noted that the attackers went beyond simple network access — they managed to obtain login credentials and passwords belonging to active users, including the IT staff responsible for defending the very systems being targeted. In response, ASIO announced the formation of dedicated teams specifically tasked with countering nation-state cyber threats to critical infrastructure.


AI, Anthropic, and the Escalating Tech Power Struggle

On the AI front, Anthropic continued its high-stakes negotiations with the White House over the release of its latest Claude Mythos 5 and Fable 5 models. Critics of the company argued that Anthropic appears to be consolidating influence at a rapid pace — a strategy the firm defends as essential to responsible AI development and safety. By Friday evening, the White House granted Anthropic authorization to make Mythos 5 accessible to a curated group of US businesses and government agencies.

Meanwhile, OpenAI rolled out an upgraded version of its GPT-5.5-Cyber model and announced a sweeping new initiative called "Patch the Planet," aimed at bolstering open source project security in areas such as vulnerability patching as AI increasingly accelerates both bug discovery and exploit development.

As the AI competition between the United States and China intensifies, WIRED spoke with several of China's leading AI researchers and found a shared anxiety on both sides: the fear of a catastrophic "Chernobyl moment" in artificial intelligence.


World Cup Scams Growing More Sophisticated

With the World Cup knockout rounds drawing near, cybersecurity experts are warning fans to exercise heightened caution. Fraudulent schemes tied to the tournament are becoming increasingly convincing and difficult to identify, targeting millions of excited soccer fans worldwide through deceptive ticket offers, fake merchandise, and phishing campaigns.

As always, staying informed and skeptical of unsolicited online deals remains the best defense.