Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Salesforce Halts Klue App Due to OAuth Token Misuse

Salesforce Halts Klue App Due to OAuth Token Misuse

Posted on June 19, 2026 By CWS

Salesforce recently announced the suspension of its integration with the Klue Battlecards app due to a security breach that affected the competitive intelligence firm on June 11, 2026. This move will prevent organizations from using the app to connect with Salesforce until further notice, as stated in a company alert.

Security Breach Details

The decision stems from Salesforce’s detection of unusual activity involving Klue’s app, which potentially led to unauthorized access to certain customer data through the app’s connection to Salesforce. Importantly, the issue is isolated to Klue’s app and does not originate from any vulnerability within Salesforce’s own system.

The breach involved a group known as Icarus, which accessed and extracted data from Klue customers, including Huntress, a cybersecurity firm. Huntress reported that the compromised data involved business contacts and sales-related information, but no sensitive data such as passwords or payment information were affected.

Klue’s Response and Investigation

Klue acknowledged unauthorized activities impacting part of its integration infrastructure on June 12, 2026. The attackers exploited a legacy credential tied to their integration service to gain entry. This access allowed them to acquire OAuth tokens used to link Klue with several third-party platforms, including Salesforce.

In response, Klue revoked compromised credentials and tokens, eliminated unauthorized code, halted remote access, and disabled potentially affected integrations. A comprehensive investigation has been launched to assess the full scope of the incident.

Analysis and Industry Impact

Some Huntress employees received threatening emails indicating that their Salesforce data had been downloaded, with demands for communication within 48 hours. The attackers utilized an outdated credential initially created by Klue for a third-party integration prototype, to infiltrate Klue’s infrastructure and steal customer tokens.

Security firm ReliaQuest observed similar tactics in the abuse of OAuth tokens, akin to previous incidents involving Salesloft Drift and Gainsight. The attackers authenticated via a compromised Klue service account, generated OAuth tokens, and executed automated scripts to extract large volumes of CRM data via Salesforce’s REST API.

Klue is in direct communication with affected customers, sharing investigative insights and assisting with response efforts. The incident highlights the vulnerabilities associated with OAuth tokens granted to third-party vendors, which often have extensive access to sensitive data yet are less frequently monitored than employee accounts.

The Icarus group’s activities reflect patterns seen in previous data theft campaigns, drawing parallels with incidents orchestrated by ShinyHunters and UNC6395. As the situation unfolds, organizations are urged to review their third-party integrations and enhance monitoring of non-human identities to mitigate similar risks in the future.

The Hacker News Tags:Cybersecurity, data breach, Huntress, Icarus group, Klue, OAuth token, ReliaQuest, Salesforce, security incident, third-party integration

Post navigation

Previous Post: China-Linked Malware Targets Middle East Telecom Firms
Next Post: Klue Supply Chain Breach Affects Cybersecurity Giants

Related Posts

Fortinet Exploit, Chrome 0-Day, BadIIS Malware, Record DDoS, SaaS Breach & More Fortinet Exploit, Chrome 0-Day, BadIIS Malware, Record DDoS, SaaS Breach & More The Hacker News
HalluSquatting Attack Threatens AI Coding Assistants HalluSquatting Attack Threatens AI Coding Assistants The Hacker News
Microsoft Office Zero-Day (CVE-2026-21509) – Emergency Patch Issued for Active Exploitation Microsoft Office Zero-Day (CVE-2026-21509) – Emergency Patch Issued for Active Exploitation The Hacker News
Critical AdonisJS Bodyparser Flaw (CVSS 9.2) Enables Arbitrary File Write on Servers Critical AdonisJS Bodyparser Flaw (CVSS 9.2) Enables Arbitrary File Write on Servers The Hacker News
FunkSec Ransomware Decryptor Released Free to Public After Group Goes Dormant FunkSec Ransomware Decryptor Released Free to Public After Group Goes Dormant The Hacker News
DarkSpectre Browser Extension Campaigns Exposed After Impacting 8.8 Million Users Worldwide DarkSpectre Browser Extension Campaigns Exposed After Impacting 8.8 Million Users Worldwide The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Feral Wolf Ransomware Exploits Exposed Business Systems
  • Abandoned CDN Domain Re-Registered, Impacting Thousands
  • Microsoft Patches Severe Azure AI Foundry Vulnerability
  • Brevo Security Breach Impacts Over 100,000 Websites
  • Transparent Tribe Unveils New Rust Backdoor Strategy

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Feral Wolf Ransomware Exploits Exposed Business Systems
  • Abandoned CDN Domain Re-Registered, Impacting Thousands
  • Microsoft Patches Severe Azure AI Foundry Vulnerability
  • Brevo Security Breach Impacts Over 100,000 Websites
  • Transparent Tribe Unveils New Rust Backdoor Strategy

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark