OAuth Supply Chain Breaches
Articles on OAuth token abuse, vendor integration compromises, and supply chain attacks leading to data theft via Salesforce, Microsoft 365, and other third-party integrations.
The AI Cybersecurity Threat Nobody's Fixing: How OAuth Abuse Is Rewriting the Rules of Supply Chain Attacks
The Klue Battlecards breach exposed a structural flaw in how enterprises trust third-party integrations. As AI agents increasingly rely on OAuth-connected APIs, the non-human identity problem is becoming the defining cybersecurity vulnerability of 2026.
Klue-Linked SaaS Supply Chain Campaign Intensifies as Extortionists Leak Extracted Salesforce CRM Data
The Icarus extortion group has begun leaking stolen CRM records, widening the impact of the Klue OAuth integration breach as additional enterprise victims confirm compromise of their Salesforce environments.
OAuth Token Abuse in Klue Integration Led to Salesforce CRM Data Theft by Icarus Group
Attackers exploited a legacy Klue integration credential to generate OAuth tokens, then used Python scripts to extract CRM data from customer Salesforce instances over 24 hours, targeting cybersecurity firms including Huntress and Tanium.