logo

Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data

ID: 3b2d9533-6cbd-5258-aec0-162113db265b

STIX ID: report--3b2d9533-6cbd-5258-aec0-162113db265b

Feed Name: CosmicBytez Labs

Threat Score
78/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

...
...

Salesforce disabled the Klue Battlecards app after a June 11, 2026 compromise of Klue that exposed stored OAuth tokens used to access downstream customer Salesforce orgs, resulting in CRM data exfiltration; affected customers (including Huntress and Recorded Future) are being notified and advised to revoke tokens, pull Event Monitoring logs for June 11–19, and audit connected apps. The incident — linked to the Icarus campaign — highlights OAuth token abuse in SaaS-to-SaaS integrations as a high-impact supply-chain attack vector.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.