Klue: SaaS supply chain compromise through long-lived OAuth tokens
ID: 5072529a-c2a5-585c-9289-5572e83c2ae9
STIX ID: report--5072529a-c2a5-585c-9289-5572e83c2ae9
Feed Name: ThreatLocker Blog
The report describes a June 12, 2026 SaaS supply-chain compromise of Klue where attackers obtained legacy service-account credentials and deployed token-theft code to collect long-lived OAuth tokens, enabling access to customer Salesforce instances and automated REST API exfiltration. The incident is linked to prior Salesloft/Drift abuses, mentions actors (UNC6395, ShinyHunters) and a newly identified actor named Icarus, lists IOCs (IPs, domains, Salesforce REST paths, user-agents, extortion phrases), and recommends revoking tokens, rotating service credentials, and tightening controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
