Salesforce disabled Klue Battlecards integration after attackers used compromised OAuth tokens to access customer CRM data via connected apps.

Market intelligence platform Klue suffered a OAuth breach that enabled the "Icarus" threat actors to steal Salesforce CRM data from multiple organizations in an ongoing extortion…

Klue's Battlecards is the third integrated app compromised to steal customers' Salesforce data; victims include Huntress, the cybersecurity vendor.