Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers' Salesforce environments, as the new "Icarus" extortion group publicly claims the attack.

Market intelligence platform Klue suffered a OAuth breach that enabled the "Icarus" threat actors to steal Salesforce CRM data from multiple organizations in an ongoing extortion…

Klue's Battlecards is the third integrated app compromised to steal customers' Salesforce data; victims include Huntress, the cybersecurity vendor.

Salesforce disabled Klue Battlecards integration after attackers used compromised OAuth tokens to access customer CRM data via connected apps.

Hackers stole data from Salesforce instances of Huntress, Recorded Future, and other Klue customers in a supply chain attack.

Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers' Salesforce…

More cybersecurity firms have disclosed the impact of the Klue supply chain attack as hackers threaten to release stolen data.

Huntress, HackerOne, Jamf, Recorded Future, and Tanium are among the cybersecurity companies that had data stolen following an earlier breach at market research firm Klue.

As yet another extortion crew Icarus exploits Salesforce-linked integrations