Klue Breach Enables Hackers to Compromise Cybersecurity Firms via OAuth Tokens
News Source : Infosecurity Magazine
News Summary
- Huntress, Recorded Future, Jamf and Tanium have all acknowledged using Klue’s intelligence services.
- The breach enabled unauthorized access to their Salesforce accounts via stolen OAuth tokens used for Klue integrations.
- Non-cybersecurity firms were also affected, including insurance service provider Insurity and social media analytics platform Sprout Social.
- Klue notified law enforcement and launched an internal investigation and comprehensive review of its security controls.
- It has now engaged CrowdStrike to support with forensics.
Several companies have disclosed that they were affected by a breach of business intelligence provider Klue, including at least five cybersecurity firms.
Never miss a story from us, subscribe to our newsletter