惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Hacker News - Newest:
Hacker News - Newest: "LLM"
S
Security Affairs
PCI Perspectives
PCI Perspectives
Google Online Security Blog
Google Online Security Blog
W
WeLiveSecurity
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Recent Commits to openclaw:main
Recent Commits to openclaw:main
P
Privacy & Cybersecurity Law Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
S
Security @ Cisco Blogs
Security Archives - TechRepublic
Security Archives - TechRepublic
Cyberwarzone
Cyberwarzone
L
Lohrmann on Cybersecurity
TaoSecurity Blog
TaoSecurity Blog
V
Visual Studio Blog
博客园 - 聂微东
Scott Helme
Scott Helme
博客园 - 【当耐特】
K
Kaspersky official blog
Security Latest
Security Latest
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
MyScale Blog
MyScale Blog
Schneier on Security
Schneier on Security
WordPress大学
WordPress大学
博客园 - 叶小钗
C
Check Point Blog
V2EX - 技术
V2EX - 技术
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - Franky
T
Tor Project blog
Apple Machine Learning Research
Apple Machine Learning Research
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
腾讯CDC
雷峰网
雷峰网
博客园_首页
美团技术团队
Y
Y Combinator Blog
C
CERT Recently Published Vulnerability Notes
AWS News Blog
AWS News Blog
月光博客
月光博客
N
Netflix TechBlog - Medium
Last Week in AI
Last Week in AI
Recent Announcements
Recent Announcements
Google DeepMind News
Google DeepMind News
Help Net Security
Help Net Security
P
Proofpoint News Feed
MongoDB | Blog
MongoDB | Blog
C
Cybersecurity and Infrastructure Security Agency CISA

BankInfoSecurity.com RSS Syndication

OnDemand | Why Cloud Intrusions Still Evade Detection Bank information security news, training, education Bank information security news, training, education Bank information security news, training, education Bank information security news, training, education Startup Geordie AI Lands $30M to Secure Enterprise AI Agents AI Exploit Risks Pushing Healthcare Security Shift Miasma Worm Hits Microsoft's AI Coding Ecosystem Senate Committee Leader Seeks Answers on NYC Health Hack Webinar | Securing the Agentic Enterprise: An Integrated Policy Framework for Enterprise AI Security Webinar | Securing the Agentic Enterprise: An Integrated Policy Framework for Enterprise AI Security AI Generated Code Is Expanding the Attack Surface What DORA, AI Oversight, and Cloud Dependency Mean for Business and Risk Leaders Why Hospitals Must Rethink Cyber Resilience Why The Privacy Risks of Embedded, Shadow AI in Healthcare The End of Static Security: Why AI Demands Real-Time Microsegmentation Anthropic Submits Pre-IPO SEC Filing, Leads Market Cap Fight AI Agents Are the New Insiders Demystifying Claude: Signal vs. Speculation Integrity or Innovation? Mixed Signals in Trump's Exec Orders Health Cyberthreat Sharing Is Advancing But Gaps Persist AI Is Reshaping Cybersecurity Training Priorities Claude Mythos 5 Can Build Exploits But Can't Power Campaigns Are Small Models Closing the Gap on Frontier AI Cyber Tools? Securing AI in Financial Services with Zero Trust Beyond the Inbox: Defending Against AI-Enabled Social Engineering Webinar | 6 Layers Standing Between Your Enterprise and AI Risk Webinar | 6 Layers Standing Between Your Enterprise and AI Risk How AI Governance Protects Patient Care and Sensitive Data Election Systems Are Now a Persistent Cyber Target DOJ, FBI Seize 13 Domains in Chinese Recruitment Op A Security Gets $37M to Thwart Weaponized AI With Automation Breach Roundup: CISA Says Agencies Should 'Patch Smarter' Joint Commission Certification Targets Healthcare AI Risks German Court: Google Liable for AI Summaries Google Sues Chinese Phishing Service Over Gemini Abuse Policy as Code: From Documents to Machine Intelligence Ozempic Drug Maker Loses Clinical Trial Data in Hack ISMG Editors: Anthropic Unleashes Claude Mythos 5 ISACA Survey: AI Adoption Is Rising, Visibility Is Not Anthropic Limits on OT Access to Mythos Draw Criticism Webinar | Frontier AI and Identity Security in Financial Services US Pulls the Plug on Anthropic 1Password Buys Apono to Expand AI Access Governance US Anthropic Export Controls Sparks Sharp EU Reaction GovSec Summit USA 2026: Cyber Resilience Amid Fiscal Reality Why AI Defenses Fail Without Data and Identity Fundamentals Geopolitics Is Now a Cybersecurity Problem Mythos Shutdown Contains a Message: Don ShinyHunters Hits Universities Via Oracle Zero-Day Labcorp Agrees to Pay $35M to Settle AMCA Data Breach US FCC Eases Router Ban for Cable ISPs How FDA Chinese Hacking Firm Upgrades With New Windows Backdoor South Korea Fines Coupang $409M Over Massive Data Breach Cyber Resilience Summit Dallas Prioritizes Risk Management Hacker: Restore Fable and Mythos Access, Cybersecurity Leaders Urge Live Webinar | Behind Dell’s AI Infrastructure Performance Rokarolla Android Banking Trojan Enables Device Takeover Ent Raises $100M to Reinvent Endpoint Security for AI Era The AI Accountability Gap CIOs Can Chinese Espionage Actor Abuses Email Rules to Steal Research Data AWS Unveils Continuum to Fight Vulnerability Backlog SpaceX Bets Big on AI Coding With $60B Cursor Deal Quantum-Safe Cryptography Isn Heart Monitoring Firm Tells SEC Hackers Stole Sensitive Data Mastra AI Framework Poisoned in npm Supply-Chain Attack Cyberspace Locked in a Nation-State Contest, Says NCSC CEO Webinar | The Future of SASE: Top 5 Predictions and Trends The Gentlemen Ransomware Gang Standardizes EDR Killing CISA Urges OT Resilience in Dark Remarks About Cyberattacks Attackers Steal Salesforce Data From Klue Battlecards Users Crime Gang Sells Access to 74,000 Fortinet Firewall Devices JPMorgan Pulls Anthropic Claude Access in Hong Kong Webinar | From SBOM to Submission: Operationalizing CRA Vulnerability Handling 6 Ways to Contain Enterprise Risk in Model Context Protocol Breach Roundup: ShinyHunters Leaks 26M MSG Records AI Inherits People Accenture Buys Majority Stake in Dragos in $4.2B Deal Multimillion-Dollar Settlement Reached in MCNA Dental Hack Addressing Quantum Readiness in Healthcare Security Cybercrime Initial Access Service SocGholish Disrupted Experts Warn of From Reflection to Shadow: AI, Us and the Space in Between ISMG Editors: Cyber Backlash Over the US Ban on Anthropic AI France and Germany Boost Digital Sovereignty Push North Korean IT Workers Try, Try, Try Again HIPAA Europe Seeks to Advance 6G Security, Privacy No Zero-Day Tied to 80,000 Harvested Fortinet Credentials Is It Time to Put Some Teeth in Post-Quantum Guidelines? New AI Model Aims to Transform Behavioral Health Lawsuits Already Getting Filed in Drug Maker Sakana AI Bets on Agent Orchestration Over Frontier Models OpenAI Lets Cyber Vendors Embed GPT-5.5 in Defenses AryStinger Botnet Converts Legacy Routers to Global Proxies Trump Executive Order Accelerates Post-Quantum Security Push North Korean Hackers Poison Mastra AI Framework
Klue Confirms OAuth Token Theft Led to Salesforce Data Heist
Mathew J. Schwartz · 2026-06-20 · via BankInfoSecurity.com RSS Syndication

Cybercrime , Fraud Management & Cybercrime , Incident & Breach Response

'Compromised Legacy Credential' Wielded by Extortion Group Calling Itself Icarus (euroinfosec) • June 19, 2026    
Klue Confirms OAuth Token Theft Led to Salesforce Data Heist
Image: Shutterstock/ISMG

Marketing intelligence platform Klue confirmed that an attacker breached its infrastructure and obtained OAuth access tokens for integrated services, using them to steal customers' Salesforce and Gong data.

See Also: Know Thy Enemy: Threats to Cyber Resilience

Klue on Thursday said it spotted the breach on June 12 and hired CrowdStrike to investigate. The company said the attack resulted in access to a system used to integrate with multiple cloud-based marketing and sales platforms (see: Attackers Steal Salesforce Data From Klue Battlecards Users).

"We immediately took steps to contain the activity, including revoking affected credentials and tokens, removing unauthorized code, disabling potentially impacted integrations, launching a comprehensive investigation and notifying law enforcement," according to a blog post signed by Klue CEO Jason Smith.

"Our investigation determined that an attacker gained access through a compromised legacy credential associated with an integration service. The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments," Smith said.

The attack first came to light publicly on Wednesday, when Salesforce announced that it had suspended all integrations from the Klue Battlecards app to its platform, following "unauthorized access to a subset of customer data via the app's connection to Salesforce.

"We are continuing to work directly with affected customers and Klue," said Salesforce, stating that "this issue is limited to Klue's app connection and does not arise from a vulnerability within the Salesforce platform."

Vancouver, British Columbia-based Klue offers a competitive intelligence platform, backed by artificial intelligence capabilities, that's designed to help customers run win-loss sales programs. Klue has yet to specify how many organizations fell victim to the attack, but did say it's reviewing its security posture and promised to strengthen it wherever possible.

Multiple Klue customers who are also security firms on Thursday reported falling victim to the Salesforce data theft. These include Huntress, Jamf, Recorded Future and Tanium. All reported finding no signs that attackers accessed anything except for Salesforce data.

Managed security service provider Huntress said Klue rapidly notified customers about the attack and has been publishing direct updates. Huntress also said its employees received ransom notes on Tuesday containing a threat to leak the data unless they began ransomware negotiations within 48 hours.

An extortion group calling itself Icarus, which claims to have been active since April 28, has listed Klue as a victim on its darknet data-leak site. "As you've probably already heard, Klue.com has been impacted by us recently. A number of other companies' Salesforce instances, which were partners to Klue, were exfiltrated," reads a post to the Icarus data leak blog.

The listing demands Klue "contact us for a swift resolution, in order not to affect the companies you work with," adding that if Klue doesn't pay a ransom, the extortionists will continue to shake down individual victims.

Huntress said the ransom emails list a Session Messenger ID for contacting the group which matches the values listed on the Icarus site.

Security experts urge companies to never pay a ransom over any type of data theft, or even to engage in communications with extortionists, warning that that escalatory tactics - including distributed-denial-of-service attacks and swatting executives - can result. The rise of more targeted, invasive pressure tactics appears to parallel a steep decline since 2024 in criminal profits from data-extortion campaigns (see: Victims Are Rebuffing Ransomware Mass Data Theft Campaigns).

Seeing CRM data posted online can be embarrassing, but such data often largely comprises customer and prospect details, and occasionally contract information or intelligence, which often wouldn't be regarded as being highly sensitive.

Even so, the data might still be useful to attacks, leading affected security firms to warn customers to watch out for spam, phishing attacks and other forms of social engineering. "Leveraging the contact information stored within Salesforce," attackers "may pose as legitimate Jamf employees and IT professionals," Jamf said.

How many third-party services Icarus breached using stolen OAuth tokens isn't clear. Huntress said that Klue told customers that it's temporarily suspended integrations between its app and not only Salesforce, but also Chorus, Clari, Gong, Google Drive, HubSpot, SharePoint, Slack App and Zoom. So far, customers have only reported seeing Salesforce as well as data for their revenue intelligence platform Gong get stolen.

Huntress said Klue customers should "consider revoking all active sessions for known-affected services in order to invalidate any potentially compromised sessions."