Cybersecurity Firms Impacted by Klue Supply Chain Attack
ID: b9f75558-81ac-51bb-9585-21e9c06bbe25
STIX ID: report--b9f75558-81ac-51bb-9585-21e9c06bbe25
Feed Name: CosmicBytez Labs
Threat Score
Klue's Salesforce integration was compromised by the Icarus campaign, allowing attackers to steal OAuth tokens and query downstream customer Salesforce tenants to exfiltrate CRM data from organizations including Huntress and Recorded Future; Salesforce has disabled the Klue app and affected customers are advised to audit connected apps, review logs, and revoke/rotate tokens.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
