As cited
Copy frozen at (site build).
breaches incidents
Scope of Salesforce Attacks Expands as Icarus Leaks Data
Attackers who breached application vendor Klue obtained OAuth tokens that enabled unauthorized access to Salesforce data belonging to Klue's customers. The scope of affected organizations has expanded beyond initial disclosures as additional victims are identified.
Why it matters: Salesforce customers using Klue integrations face potential exposure of business data and customer information; practitioners should audit Klue OAuth token permissions, revoke compromised credentials, and verify Salesforce activity logs for unauthorized access.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
Scope of Salesforce Attacks Expands as Icarus Leaks Data
Attackers who breached application vendor Klue obtained OAuth tokens that enabled unauthorized access to Salesforce data belonging to Klue's customers. The scope of affected organizations has expanded beyond initial disclosures as additional victims are identified.
Why it matters: Salesforce customers using Klue integrations face potential exposure of business data and customer information; practitioners should audit Klue OAuth token permissions, revoke compromised credentials, and verify Salesforce activity logs for unauthorized access.
- Source published
- First seen by Cybersecurity Tracker