Scope of Salesforce Attacks Expands as Icarus Leaks Stolen Data
ID: b93e37a0-385f-5c1a-bb3b-27e848de70a6
STIX ID: report--b93e37a0-385f-5c1a-bb3b-27e848de70a6
Feed Name: CosmicBytez Labs
A supply-chain breach of Klue resulted in attackers stealing OAuth tokens Klue held for customer Salesforce integrations; the Icarus threat actor used those tokens to access multiple customer Salesforce orgs, exfiltrate CRM records and PII, and publicly leak portions of the stolen data. The report details the attack chain, scope and impact, systemic risks of vendor OAuth delegation, and provides immediate and longer-term mitigation guidance (revoking tokens, auditing connected apps, IP allowlisting, least-privilege scopes, and token rotation).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
