news.mlab.sh
Back to the feed
threat-intel

Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data

High
Image: The Hacker News
Summary

Salesforce disabled the Klue Battlecards app integration following a security incident where the Icarus extortion group exploited compromised credentials to access customer data via Salesforce. The attackers leveraged a legacy credential to steal OAuth tokens, enabling them to query connected customer environments and exfiltrate business contacts and price quotes. Huntress, a cybersecurity company, was impacted, receiving a threatening email demanding payment. The incident highlights the risks associated with third-party integrations and the abuse of OAuth tokens.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.