reliaquest.com • 5w
Klue Supply Chain Compromise: OAuth Token Abuse and Salesforce Data Exfiltration
The threat actor group Icarus executed a supply chain attack by compromising the backend systems of the Klue 'Battlecards' integration service. By harvesting stored OAuth tokens, attackers bypassed traditional perimeter security and multi-factor authentication (MFA) to impersonate the trusted Klue application within customer Salesforce CRM instances. Utilizing the Salesforce REST API, the actors performed bulk exfiltration of sensitive enterprise data, including customer records and sales pipelines. This incident highlights the systemic risk posed by third-party SaaS integrations, where a compromise of a trusted service provider facilitates unauthorized, authenticated access to interconnected enterprise environments.
Links:reliaquest.com, SC Media, techjacksolutions.com, gbhackers.com, feeds.feedburner.com, helpnetsecurity.com, Obsidiansecurity, Status, bleepingcomputer.com, Ampcuscyber, Recordedfuture, Rescana, Tanium, Dexpose, Ghost-protocol, Threatcodex, Huntress, Darkreading, Salesforceben, Kudelskisecurity, Techechelon, Govinfosecurity, Radar, Csidb, Thecybersecguru, Socdefenders, News4Hackers, Aiweekly, threatlocker.com, threat-modeling.com, csoonline.com, fieldeffect.com, cybersecuritydive.com, Iansresearch, App, Rhisac, Rodtrent, Techradar, Securitylabs, Galaxywarden, Blog, Klue, Medium, Youtube, Hawk-eye, Thenextweb, Channelinsider, Beazley, Mashable, Computing, Reddit, Pcmag, Upguard, Zscaler, SecurityWeek •