Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Salesforce Halts Klue App Due to OAuth Token Misuse

Salesforce Halts Klue App Due to OAuth Token Misuse

Posted on June 19, 2026 By CWS

Salesforce recently announced the suspension of its integration with the Klue Battlecards app due to a security breach that affected the competitive intelligence firm on June 11, 2026. This move will prevent organizations from using the app to connect with Salesforce until further notice, as stated in a company alert.

Security Breach Details

The decision stems from Salesforce’s detection of unusual activity involving Klue’s app, which potentially led to unauthorized access to certain customer data through the app’s connection to Salesforce. Importantly, the issue is isolated to Klue’s app and does not originate from any vulnerability within Salesforce’s own system.

The breach involved a group known as Icarus, which accessed and extracted data from Klue customers, including Huntress, a cybersecurity firm. Huntress reported that the compromised data involved business contacts and sales-related information, but no sensitive data such as passwords or payment information were affected.

Klue’s Response and Investigation

Klue acknowledged unauthorized activities impacting part of its integration infrastructure on June 12, 2026. The attackers exploited a legacy credential tied to their integration service to gain entry. This access allowed them to acquire OAuth tokens used to link Klue with several third-party platforms, including Salesforce.

In response, Klue revoked compromised credentials and tokens, eliminated unauthorized code, halted remote access, and disabled potentially affected integrations. A comprehensive investigation has been launched to assess the full scope of the incident.

Analysis and Industry Impact

Some Huntress employees received threatening emails indicating that their Salesforce data had been downloaded, with demands for communication within 48 hours. The attackers utilized an outdated credential initially created by Klue for a third-party integration prototype, to infiltrate Klue’s infrastructure and steal customer tokens.

Security firm ReliaQuest observed similar tactics in the abuse of OAuth tokens, akin to previous incidents involving Salesloft Drift and Gainsight. The attackers authenticated via a compromised Klue service account, generated OAuth tokens, and executed automated scripts to extract large volumes of CRM data via Salesforce’s REST API.

Klue is in direct communication with affected customers, sharing investigative insights and assisting with response efforts. The incident highlights the vulnerabilities associated with OAuth tokens granted to third-party vendors, which often have extensive access to sensitive data yet are less frequently monitored than employee accounts.

The Icarus group’s activities reflect patterns seen in previous data theft campaigns, drawing parallels with incidents orchestrated by ShinyHunters and UNC6395. As the situation unfolds, organizations are urged to review their third-party integrations and enhance monitoring of non-human identities to mitigate similar risks in the future.

The Hacker News Tags:Cybersecurity, data breach, Huntress, Icarus group, Klue, OAuth token, ReliaQuest, Salesforce, security incident, third-party integration

Post navigation

Previous Post: China-Linked Malware Targets Middle East Telecom Firms
Next Post: Klue Supply Chain Breach Affects Cybersecurity Giants

Related Posts

Critical Metro4Shell Vulnerability Exploited in React Native Critical Metro4Shell Vulnerability Exploited in React Native The Hacker News
Critical RCE Flaws in Cisco ISE and ISE-PIC Allow Unauthenticated Attackers to Gain Root Access Critical RCE Flaws in Cisco ISE and ISE-PIC Allow Unauthenticated Attackers to Gain Root Access The Hacker News
Google Takes Legal Action Against Chinese AI-Driven Phishing Ring Google Takes Legal Action Against Chinese AI-Driven Phishing Ring The Hacker News
What 2025 Is Teaching Us About Cloud Defense What 2025 Is Teaching Us About Cloud Defense The Hacker News
Microsoft Patches 130 Vulnerabilities, Including Critical Flaws in SPNEGO and SQL Server Microsoft Patches 130 Vulnerabilities, Including Critical Flaws in SPNEGO and SQL Server The Hacker News
Noisy Bear Targets Kazakhstan Energy Sector With BarrelFire Phishing Campaign Noisy Bear Targets Kazakhstan Energy Sector With BarrelFire Phishing Campaign The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CryptoBandits Malware Abuses Tor for RCE and Data Theft
  • Access Control: The New Challenge of Shadow AI
  • Sophisticated Crypto Clipper Malware Targets USB Drives
  • FortiBleed Campaign Compromises 86,000 Fortinet Devices
  • Node.js Security Update Addresses Critical Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CryptoBandits Malware Abuses Tor for RCE and Data Theft
  • Access Control: The New Challenge of Shadow AI
  • Sophisticated Crypto Clipper Malware Targets USB Drives
  • FortiBleed Campaign Compromises 86,000 Fortinet Devices
  • Node.js Security Update Addresses Critical Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark