Threat Intelligence Brief
Curated summary with source attribution
Source: csoonline.com
Threat Risk: High
Victim: Klue and its enterprise customers
Incident: A SaaS supply chain breach leveraging stolen OAuth tokens to access third-party CRM data.
Impact: Unauthorized extraction of sensitive customer contact information, pricing data, and sales communications.
Attacker: Icarus criminal group
Analysis: The Icarus criminal group exploited an unused service account to harvest OAuth tokens, bypassing traditional password security to impersonate Klue. By leveraging these trusted relationships, the attackers accessed integrated customer environments to exfiltrate sensitive CRM data via Salesforce APIs. This incident highlights a shift toward identity-based attacks that target session tokens rather than static credentials.
Recommendations: Audit and rotate all OAuth tokens and service account credentials on a strict schedule.; Implement strict least-privilege permissions for all SaaS-to-SaaS integrations.; Establish continuous monitoring for anomalous API query volumes within integrated cloud platforms.
Source: CSO Online
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source