Salesforce Data Thefts Continue via Klue App Compromise
ID: 061dc9c4-b401-50be-88ec-4ccb84595d82
STIX ID: report--061dc9c4-b401-50be-88ec-4ccb84595d82
Feed Name: CosmicBytez Labs
The report describes the Icarus campaign, where attackers compromise third-party SaaS apps (e.g., Klue Battlecards) and abuse long-lived, over-permissioned OAuth/API credentials to exfiltrate Salesforce CRM data across many customer organizations; Huntress is confirmed as a victim. The campaign demonstrates a high-impact SaaS-to-SaaS supply-chain risk and recommends OAuth token audits, least-privilege scopes, third-party security assessments, connected-app monitoring, and rapid token revocation runbooks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
