[Security Digest] 24 billion passwords leaked: is one of them yours?
Three confirmed breaches, a browser zero-day already under attack, and 24 billion passwords sitting in a single database left open to the internet. That was the week. Here is what happened and, more importantly, what to actually do about it.
The Big 3
Update Chrome today: a zero-day is being exploited right now
Google shipped an emergency fix on 9 June for CVE-2026-11645, a flaw in V8, the engine that runs JavaScript inside Chrome. It was being used in real attacks before the patch landed. A bug like this can let a booby-trapped web page run code on your machine just from a visit. No click, no download.
What to do: open Chrome, go to Help, then About Google Chrome, let it update, then click Relaunch. The relaunch is the step people skip, and until you do it you are still exposed. Same goes for Edge, Brave and other Chromium browsers. Read more →
24 billion stolen credentials turned up in one exposed database
On 12 June, researchers at Cybernews found an 8.3 terabyte database holding roughly 24 billion credential records sitting open online. The unsettling part is what was inside: mostly fresh infostealer logs, many with a username, a plaintext password and the exact site it unlocks. Not hashed. In the clear. If you reuse passwords, this is how one leaked login becomes ten compromised accounts.
What to do: check your email at haveibeenpwned.com, then change any reused password, starting with your email account, and turn on two-factor authentication. Read more →
The companies that secure everyone else just got breached through a vendor
Market intelligence firm Klue disclosed on 19 June that attackers stole customer data through its Salesforce integration between 11 and 12 June. The customers caught up in it are not random: HackerOne, Huntress, OneTrust and Snyk, all security companies. Nobody breached them directly. A tool they had wired into their systems got compromised, and the data walked out through that door. A group calling itself Icarus has claimed it.
Why this matters: if you run a business, your security is only as strong as the weakest vendor you have given access to. Audit your connected apps and revoke the ones nobody uses. Read more →
Quick Hits
Microsoft patched 200 flaws, six of them zero-days. June's Patch Tuesday was a heavy one. If you are on Windows, run Windows Update and restart. The restart is what actually applies the fixes. Read more → (3 minute read)
Texas Parks and Wildlife breach may hit three million people. Driver's licence and passport numbers were among the data exposed, the kind you cannot simply reset. Watch for convincing phishing and consider a credit freeze. Read more → (3 minute read)
France's CNIL fines IQVIA 5 million euros over health data. Issued on 26 May, it is 2026's largest single GDPR penalty so far. Enforcement keeps landing on the same basics: lawful basis, real consent and tight vendor controls. Read more → (3 minute read)
Tool of the Week
A password manager that generates and stores a unique password for every account, so a leak at one site cannot unlock the rest.
For you if you have more than a handful of online accounts and still reuse the same two or three passwords across half of them. After this week's 24 billion record leak, that is most people.
Honest caveat: the free tier is generous and covers unlimited passwords on one account, but family sharing and some extras sit behind a low yearly fee. If you already use 1Password or your browser's built-in manager properly, you do not need to switch.
Protect Yourself
Five minutes, one habit: go to haveibeenpwned.com and enter your main email address. It will show you which known breaches your address has appeared in, for free. For every account it flags where you reused a password, change it to a unique one and switch on two-factor authentication. Start with your email, because that is the account attackers use to reset everything else.
Forward this to someone who cares about staying secure. They'll thank you.
Free weekly security briefing: futuretechnologyhq.com/newsletter
Some links in this newsletter may be affiliate links. We only recommend products we genuinely think are worth your time.