Klue Supply Chain Compromise and CRM Data Exfiltration Incident Advisory
ID: a819fd51-007c-5165-a261-8d28ca2e6cf1
STIX ID: report--a819fd51-007c-5165-a261-8d28ca2e6cf1
Feed Name: Kudelski Security
A supply-chain compromise of the Klue platform led to malicious backend code that harvested customer OAuth tokens; those tokens were then used to authenticate into downstream SaaS services (including Salesforce, HubSpot, Google Drive, Slack and others) to perform automated, bulk CRM and sales data exfiltration. The report provides technical telemetry (abnormal /services/data/v59.0/query/ activity, Python-urllib user agents, non-standard User-Agent values), four IP IOCs, and mitigation guidance such as immediate token revocation, log review, and vendor coordination.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
