More Cybersecurity Firms Disclose Impact From Klue Hack

https://www.securityweek.com/wp-content/uploads/2024/12/blockchain-cryptocurrency-Solana.jpeg

At least nine organizations have publicly acknowledged the impact of the supply chain attack on market intelligence platform Klue.

The incident occurred on June 11-12 and affected Klue’s integration with Salesforce, resulting in data being exfiltrated from the Salesforce instances of multiple Klue customers, including several cybersecurity firms.

On Friday, Klue confirmed previous security reports that the attackers used compromised legacy credentials to access its systems and compromise Salesforce integrations.

“The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments,” Klue said.

The company revoked the affected credentials and tokens, disabled the integrations across multiple services, and has been investigating the attack together with CrowdStrike and law enforcement.

“Based on our investigation to date, the incident was limited to the affected third-party platforms, and there is no evidence that customer...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more