Klue Supply Chain Breach Exposes Salesforce Data At Several Security Firms

https://informationsecuritybuzz.com/wp-content/uploads/Klue-supply-chain-breach.jpg

A supply chain attack targeting Klue, a competitive intelligence platform, has lead to the theft of Salesforce data from multiple entities, including several cybersecurity vendors.

Klue disclosed that threat actors had gained unauthorized access to part of its integration infrastructure in June after compromising a legacy credential linked to a backend system.

“Our investigation determined that an attacker gained access through a compromised legacy credential associated with an integration service. The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce,” Klue said.

According to incident investigations published by Huntress and other affected companies, the stolen tokens were then used to access customer Salesforce environments and exfiltrate CRM data directly from victim systems.

Huntress said the attack began around June 11 and involved unauthorized code updates to Klue’s integration services.

Leveraging trusted application permissions

Several security companies have confirmed they were affected....

Copyright of this story solely belongs to informationsecuritybuzz.com. To see the full text click HERE

Read more