惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
V2EX
Y
Y Combinator Blog
博客园_首页
V
Visual Studio Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
阮一峰的网络日志
阮一峰的网络日志
Hugging Face - Blog
Hugging Face - Blog
宝玉的分享
宝玉的分享
B
Blog
博客园 - 三生石上(FineUI控件)
小众软件
小众软件
WordPress大学
WordPress大学
L
LangChain Blog
爱范儿
爱范儿
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
P
Proofpoint News Feed
Blog — PlanetScale
Blog — PlanetScale
C
Check Point Blog
博客园 - 聂微东
云风的 BLOG
云风的 BLOG
Microsoft Security Blog
Microsoft Security Blog
博客园 - 叶小钗
酷 壳 – CoolShell
酷 壳 – CoolShell
H
Help Net Security

Hackread – Cybersecurity News, Data Breaches, AI and More

Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks New GhostShell Hacking Group Targets Ukraine’s Drone Defense Sector Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords Best Crypto Payment Solutions for E-Commerce Businesses Internet Society Foundation Opens Global Call for Common Good Cyber Fund to Strengthen Cybersecurity ‘Cordyceps’ CI/CD Flaw Exposes Microsoft, Google, Apache Repos to Pipeline Hijacking The Rise of AI-Powered Academic Fraud: Beyond Traditional Plagiarism New CryptoBandits Malware Uses USB Drives and Tor to Steal Crypto The Evolution of iGaming Fraud: What Security Teams Should Expect in 2027 2 Scattered Spider-Linked Hackers Plead Guilty Over £39M TfL Cyberattack Beats Studio Buds Flaw Could Let Nearby Attackers Eavesdrop on Users Texas Parks and Wildlife Data Breach Affects Over 3M License Customers Threat Hunting Beyond Alerts: Finding the Activity Detection Misses Scammers Use Fake GitHub Stars, VirusTotal Reviews to Spread Crypto Clipper Salesforce Disables Klue Integration After OAuth Token Theft Hits Customer Data MDR Provider Comparison: Time to Discover and Respond to Threats Meteor 3.0 Migration Helped Rocket.Chat Move Off End-of-Life Node.js Runtime Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections Nintendo America Employee Data Exposed After Shadowbyt3$ Targets TinyPulse eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks FIFA World Cup 2026: Hackers Target Football Fans With Fake Tickets Sites MacBook Neo vs Windows Laptops for Cybersecurity Tasks Operation Endgame Disrupts SocGholish Malware Infrastructure What Businesses Should Know Before Migrating Their CMS DragonForce Ransomware Abused Microsoft Teams to Hide Malware Activity Agentjacking: Researchers Show How One Fake Bug Report Can Hijack AI Coding Agents FortiBleed Attack Exposes Fortinet Firewall Credentials in 194 Countries SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies 152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Fake Search Clicks Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It
LastPass Confirms Customer Data Breach After Klue OAuth T...
Waqas · 2026-06-24 · via Hackread – Cybersecurity News, Data Breaches, AI and More

LastPass has confirmed it was affected by the Klue supply chain incident, saying an unauthorised actor used stolen OAuth tokens from the third-party market intelligence platform to access customer data stored in its Salesforce environment.

The company said it learned of the Klue incident on June 12, 2026, after Klue, a market intelligence platform used by LastPass go-to-market teams, notified customers about unauthorised activity. Klue integrates with business tools, including Salesforce and Gong, which made the stolen tokens valuable because they could be used to reach connected customer systems without needing normal login credentials.

According to LastPass, the exposed data was limited to customer relationship management information inside Salesforce. This included customer names, phone numbers, email addresses, physical addresses, support case data, and sales-related records. The company said LastPass products, services, infrastructure, and customer vaults were not affected.

The incident follows earlier reporting that Salesforce disabled Klue Battlecards’ integration infrastructure on June 17, 2026, after detecting unusual activity involving the app’s connection to Salesforce. Salesforce said the issue was limited to Klue’s app connection and did not come from a vulnerability in the Salesforce platform itself.

The Klue incident has already been linked to data theft from several companies using the platform. The group behind these attacks is a new extortion group named Icarus, after it gained access to Klue’s backend systems, pushed a malicious code update, and harvested OAuth tokens used by customer integrations. Those tokens were then used to query Salesforce environments and copy CRM data.

LastPass Confirms Customer Data Breach After Klue OAuth Token Theft
Icarus on its dark web leak site (Image credit: Hackread.com)

OAuth tokens are designed to let connected applications share information without asking users to log in repeatedly. That convenience also creates risk when a third-party service holding those tokens is compromised, because attackers may be able to access connected systems until the tokens are revoked or rotated.

LastPass said it has completed remediation and rotated the exposed Klue OAuth tokens. The company also discontinued employee access to Klue, launched an investigation with Klue and Salesforce, and notified law enforcement. Its ongoing response includes sharing technical details with the security community and adding safeguards to reduce the chance of similar incidents.

For customers, LastPass advised caution around phishing and social engineering attempts, since exposed contact details and CRM records can be used to make scams look more credible. The company also reminded users that LastPass staff will never ask for a master password and that official support communication should come through trusted LastPass channels.

The company published indicators of compromise connected to the incident, including IP addresses and email sender domains. Those details are meant to help organisations review logs and spot activity linked to the Klue campaign.

LastPass Confirms Customer Data Breach After Klue OAuth Token Theft
Klue supply chain attack explained

The Klue case adds to a run of incidents where attackers abused third-party application access to reach Salesforce data. In earlier cases, compromised app tokens and integrations were used to pull large volumes of CRM information from customer environments. These incidents show how SaaS connections can become an entry point even when the main platform is not directly breached.

If your company is using integrated sales and marketing tools, the LastPass disclosure is a prime example to review which apps have access to CRM data, revoke unused connections, rotate tokens after vendor incidents, and monitor API activity for unusual data exports.