Klue confirmed attackers stole OAuth tokens for Salesforce integrations after a June 12 breach using a compromised legacy credential. The Icarus extortion group publicly claimed the attack. Huntress and ReliaQuest detailed how stolen tokens enabled large-scale Salesforce data theft via Python scripts. Klue revoked credentials and engaged CrowdStrike.
Tap to vote and see what everyone thinks.
Summary by ByteBrief
The Vimeo breach and the dangers of delegated trust