惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
Martin Fowler
Martin Fowler
Last Week in AI
Last Week in AI
罗磊的独立博客
阮一峰的网络日志
阮一峰的网络日志
博客园 - 【当耐特】
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 三生石上(FineUI控件)
S
SegmentFault 最新的问题
V
Visual Studio Blog
Hugging Face - Blog
Hugging Face - Blog
雷峰网
雷峰网
博客园_首页
人人都是产品经理
人人都是产品经理
量子位
美团技术团队
The Cloudflare Blog
小众软件
小众软件
WordPress大学
WordPress大学
有赞技术团队
有赞技术团队
M
MIT News - Artificial intelligence
Microsoft Security Blog
Microsoft Security Blog
D
DataBreaches.Net
博客园 - Franky

Recorded Future

The Threat Isn’t the Frontier Model Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool Where Expertise Meets Algorithm: The Insikt Group® Intelligence Edge Evaluating Mexico’s New Cybersecurity Plan The Purchase Scam Tactic Headed for the World Cup | Recorded Future FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems State Digital Surveillance Risk Landscape The Intelligence No One Else Has: Inside Recorded Future’s Proprietary Collection Engine The Intelligence No One Else Has: Inside Recorded Future’s Proprietary Collection Engine Cyber-Enabled Maritime Sanctions Evasion Recorded Future Launches Impact and Metrics Dashboard 2026 FIFA World Cup: What Public Safety Officials Need to Know China's Noncombatant Evacuation Operations: 2005–2025 Russia’s Defense-Based Economy Risks Forcing Putin to Fight Wars May 2026 CVE Landscape Why Holistic Sourcing Wins: The Numbers Behind the Recorded Future Advantage Threats to the 2026 FIFA World Cup Remembering Sir Alex Younger Iran Expands Handala Brand to Physical Threats The Vulnerability Flood Is Now a Board Conversation. Here's How to Lead It. At Mythos Speed: A Defender's Playbook for the AI Vulnerability Surge in 2026 April 2026 CVE Landscape Beyond Acceleration and Automation: How AI + Intelligence Changes Cyber Defense NIST NVD Enrichment Policy Change: Prioritizing Vulnerabilities with Attacker Behavior Signals A Complete History of Cybersecurity: From Early Viruses to AI-Powered Threats The Different Types of Payment Fraud and How to Prevent Them Digital Citizenship Glossary: Key Terms Every Internet User Should Know Quantum Risk Explained Threat Activity Enablers: The Backbone of Today’s Threat Landscape Recorded Future Named a Leader in the 2026 Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies. And there’s more.
The Klue Security Incident and Its Impact on Recorded Future
Recorded Future® · 2026-06-18 · via Recorded Future

The following message was shared with Recorded Future customers and partners earlier today.

At Recorded Future, we've long believed that transparency and information sharing are among the most powerful tools in cybersecurity. They're core to what we do — helping organizations understand threats so they can act on them. That same principle applies to us.

With that in mind, we are sharing details of a recent security incident involving Klue, a third-party marketing vendor we use, which impacted us and other organizations.

What Happened

This week, Recorded Future's CSIRT was notified that Klue had identified unauthorized access to its environment that affected the integration layer used to connect Klue with other marketing and sales SaaS platforms. According to Klue, the unauthorized activity began on June 12, 2026, and was contained the same morning.

Our security team has since conducted its own investigation, correlating activity logs across Klue and any services that were integrated with Klue.

All available evidence suggests that Recorded Future was not specifically targeted and was instead an incidental victim by virtue of utilizing the compromised integration between Salesforce and Klue.

There is no evidence that Recorded Future's proprietary systems, internal databases, or customer platform data have been accessed or compromised.

What We Found

On June 17, we confirmed that elements of Recorded Future’s Salesforce account were impacted via a compromised OAuth token associated with an integration between Salesforce and Klue.

While our investigation is ongoing, we believe the impact was limited to business data fields stored in our Salesforce database, such as client contact names and email addresses. Certain business contract information may also have been potentially included in the impacted data. We continue to investigate the full scope of the exposure and will update this blog as we learn more.

What We Did

Upon confirming the scope of the incident, our incident response team:

  • Locked down and revoked all associated OAuth tokens connected to the Klue integration
  • Engaged Salesforce directly to obtain additional logs and support
  • Launched a review of all integrated Salesforce third-party applications
  • Correlated known malicious IP addresses identified by Klue against our own environment logs
  • Continued active monitoring of our systems for any further anomalous activity
  • Communicated with Law Enforcement to respond appropriately

What This Means

The incident was limited to the third-party integration layer between Salesforce and Klue — it did not touch Recorded Future's core platform, Intelligence Graph, or any internal infrastructure.

There is no action required on the part of Recorded Future customers at this time, except for basic cyber-hygiene and continued vigilance for any phishing activity or spam.

Further, Recorded Future has published a Note to the Platform regarding this incident to allow customers to research their potential exposure to the Klue ecosystem.

Moving Forward

The security of your information is of paramount importance to Recorded Future. We will maintain our continued, ongoing reviews of our SaaS security posture management and logging program, as well as third- and fourth-party access, to understand what improvements can be made to enhance our existing protections.

We will continue to investigate this incident, and we are committed to keeping you informed if any significant new information becomes available.