Salesforce Disables Klue Integration After AI Intelligence Vendor Is Hacked
Klue provides AI-powered competitive intelligence and Battlecards software that businesses can connect to third-party platforms such as Salesforce through OAuth. The incident stemmed from unauthorized access to Klue’s integration infrastructure and the exposure of OAuth tokens, potentially giving attackers access to customer data. It also highlighted the risks posed by a single point of failure in the SaaS supply chain.
As of June 24, the Klue supply-chain attack had affected organizations including Gong, Huntress and LastPass, with at least 10 cybersecurity companies impacted. LastPass also confirmed the exposure of customer contact and support data. Salesforce disabled the Klue Battlecards application connection, while Klue engaged CrowdStrike to investigate, revoked tokens and implemented response measures.
All Coverage
5 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.