Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data
ID: 3b2d9533-6cbd-5258-aec0-162113db265b
STIX ID: report--3b2d9533-6cbd-5258-aec0-162113db265b
Feed Name: CosmicBytez Labs
Salesforce disabled the Klue Battlecards app after a June 11, 2026 compromise of Klue that exposed stored OAuth tokens used to access downstream customer Salesforce orgs, resulting in CRM data exfiltration; affected customers (including Huntress and Recorded Future) are being notified and advised to revoke tokens, pull Event Monitoring logs for June 11–19, and audit connected apps. The incident — linked to the Icarus campaign — highlights OAuth token abuse in SaaS-to-SaaS integrations as a high-impact supply-chain attack vector.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
