惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

罗磊的独立博客
Recent Announcements
Recent Announcements
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
有赞技术团队
有赞技术团队
J
Java Code Geeks
T
The Blog of Author Tim Ferriss
MyScale Blog
MyScale Blog
人人都是产品经理
人人都是产品经理
aimingoo的专栏
aimingoo的专栏
U
Unit 42
The GitHub Blog
The GitHub Blog
云风的 BLOG
云风的 BLOG
T
Tailwind CSS Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 三生石上(FineUI控件)
Apple Machine Learning Research
Apple Machine Learning Research
小众软件
小众软件
Hugging Face - Blog
Hugging Face - Blog
博客园 - 司徒正美
腾讯CDC
I
InfoQ
GbyAI
GbyAI
博客园_首页

Google adds end-to-end Gmail encryption to Android, iOS devices for enterprises | CSO Online

Die besten DAST- & SAST-Tools CISA mulls new three-day remediation deadline for critical flaws CISA pushes critical infrastructure operators to prepare to work in isolation CISOs step up to the security workforce challenge 10 Anzeichen für einen schlechten CSO Anthropic Mythos spurs White House to weigh pre-release reviews for high-risk AI models Security agencies draw red lines around agentic AI deployments The fake IT worker problem CISOs can’t ignore How CISOs should utilize data security posture management to inform risk Was ist ein Botnet? Human-centric failures: Why BEC continues to work despite MFA Just 34% of cyber pros plan to stick with their current employer Managing OT risk at scale: Why OT cyber decisions are leadership decisions 4 ways to prepare your SOC for agentic AI ‘Trivial’ exploit can give attackers root access to Linux kernel Bank regulator sounds warning over cybersecurity threat posed by AI models Dismantle implicit trust in OT networks, CISA tells critical infrastructure operators Max-severity RCE flaw found in Google Gemini CLI Stopping the quiet drift toward excessive agency with re-permissioning ODNI to CISOs on threat assessments: You’re on your own 10 wichtige Security-Eigenschaften: So setzen Sie die Kraft Ihres IT-Sicherheitstechnik-Teams frei Researchers unearth industrial sabotage malware that predated Stuxnet by 5 years AWS leans on prior ingenuity to face future AI and quantum threats What it takes to win that CSO role Third Party Risk Management: So vermeiden Sie Compliance-Unheil Critical Cursor bug could turn routine Git into RCE Securing RAG pipelines in enterprise SaaS What CISOs need to get right as identity enters the agentic era Stopping AiTM attacks: The defenses that actually work after authentication succeeds EDR-Software – ein Kaufratgeber
Klue breach exposed Salesforce CRM data through stolen OA...
Gyana Swain · 2026-06-23 · via Google adds end-to-end Gmail encryption to Android, iOS devices for enterprises | CSO Online

Cybersecurity firms were among those caught up in the breach.

An attacker broke into competitive-intelligence vendor Klue, stole OAuth tokens its customers use to connect to Salesforce and other platforms, and accessed data across multiple customer environments prompting the company to revoke customer OAuth tokens and disable affected integrations.

“An attacker gained access through a compromised legacy credential associated with an integration service,” Klue CEO Jason Smith said in a posting to the company’s blog. “The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments,” he wrote.

Klue detected the intrusion on June 12 and Smith posted to the blog on June 19.

The breach reached Salesforce accounts at cybersecurity vendors Huntress and Recorded Future, along with an undisclosed number of other Klue customers.

Salesforce disabled the Klue Battlecards integration and said organizations cannot reconnect through it until further notice, saying in a posting to its website, “Our security teams recently detected unusual activity involving the app that may have resulted in unauthorized access to a subset of customer data via the app’s connection to Salesforce. This issue is limited to Klue’s app connection and does not arise from a vulnerability within the Salesforce platform.”

Unauthorized code removed

Klue’s CEO listed the containment steps the company had taken, including revoking affected credentials and tokens, disabling impacted integrations, notifying law enforcement — and “removing unauthorized code.” He offered no further detail on the unauthorized code, how it arrived, or what it did. The company did not immediately respond to a request for further details of its removal of unauthorized code.

Security vendor and Klue customer Huntress published its own investigation filling in that gap. The attackers had pushed a code update to a Klue integration system designed to harvest customers’ OAuth tokens, Huntress wrote. Klue staff later found the ‘token-theft code’ and removed it, Huntress added in its investigation report.

The initial entry point was a credential Klue had created to prototype an integration it later dropped but never deactivated. “The threat actor seems to have leveraged a long-disused but still active credential to conduct the initial compromise — one that was originally created by Klue for them to prototype a third-party integration they later abandoned,” Huntress said. The attacker then pivoted through Klue’s infrastructure, collected customer tokens and used them to query those customers’ CRM systems before exfiltrating the data, the firm added.

Klue shut down integrations with Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive and Slack and issued a general alert on June 13, according to Huntress. That alert “did not indicate which customers were impacted,” the firm noted. It did not name any affected customers.

Another security firm, ReliaQuest, traced how customer CRM data was pulled from Salesforce. The attacker authenticated to victims’ Klue integration service accounts, generated OAuth tokens and ran automated Python scripts that queried the Salesforce REST API for about 24 hours, ReliaQuest said in its threat analysis.

The activity was consistent with bulk data retrieval rather than routine integration traffic, it noted — a distinction that would not have been visible without API-layer logging.

ReliaQuest advised organizations that had connected Klue to Salesforce to treat the incident as a prompt to revoke and rotate all OAuth tokens and refresh tokens tied to that integration, review Salesforce API logs for unusual query volumes, and restrict third-party integration accounts to known IP ranges.

“Any third-party app with OAuth access to a core platform like Salesforce is part of your attack surface and should be inventoried, monitored, and scoped to least privilege,” the firm said.

Salesforce and Gong data taken

Huntress confirmed it was among the affected customers. Business contacts, price quotes and sales communications from its Salesforce account were taken, the company said. Passwords, payment-card data, threat intelligence and product telemetry were not compromised, and the Huntress product and infrastructure were untouched.

Parts of the Salesforce account at another cybersecurity vendor, Recorded Future, were also accessed, the company said. “All available evidence suggests that Recorded Future was not specifically targeted and was instead an incidental victim by virtue of utilizing the compromised integration between Salesforce and Klue,” Recorded Future said. The exposure appeared limited to client contact names, email addresses and possibly some contract information, it added.

Icarus claims the attack

Huntress attributed the attack to a new extortion group calling itself Icarus, after session messenger IDs in extortion emails matched identifiers on the group’s dark-web leak site. Icarus listed Klue publicly on June 19 and said it had exfiltrated Salesforce data from a number of Klue’s partner companies. The group has signaled it may contact affected organizations directly, meaning Klue customers should expect unsolicited outreach and review their spam folders for related emails, Huntress said.

The activity matched the OAuth-abuse pattern behind the 2025 Salesloft Drift and Gainsight compromises, tied to ShinyHunters and UNC6395, but evidence was insufficient to link the Klue incident to either group, the firm said.

“The OAuth-abuse playbook is repeatable, effective, and now widely adopted,” it warned.

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.