Salesforce Disables Klue Integration After OAuth Token Theft Hits Customer Data

https://hackread.com/wp-content/uploads/2026/06/salesforce-disables-klue-integration-oauth-token-data.png

A new supply chain attack has targeted companies using Salesforce. Attackers compromised a third-party application integration, Klue Battlecards, to access and steal customer data. Salesforce disabled the app’s integration infrastructure on 17 June 2026 to stop unauthorised access, clarifying that the issue was limited to Klue and not a vulnerability in the Salesforce platform itself.

“Our security teams recently detected unusual activity involving the app that may have resulted in unauthorized access to a subset of customer data via the app’s connection to Salesforce. This issue is limited to Klue’s app connection and does not arise from a vulnerability within the Salesforce platform,” Salesforce’s alert reads.

How the Breach Happened

Cybersecurity firm Huntress found that the initial breach occurred on 11 June, noting that attackers entered Klue’s backend system by exploiting an old, unused testing credential that was still somehow active. Once inside, they deployed a malicious code update...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE

Read more

https://cdn.mos.cms.futurecdn.net/9Z9K5UaMGTkqQXxzzpPkZ-2560-80.jpg

Quote of the day by pioneer of cybernetics Norbert Wiener: 'The automated machine is the economic equivalent of slave labour' — foreshadowing the displacement of human labor in the years to come

For as long as humanity has envisioned a future co-existing with machines, there have been fears that labor could be displaced. These fears first sparked during the Industrial Revolution in the 1800s, but have continued in the years since. Most recently, the rise of generative AI has raised these fears