Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
4 / 4 results
highbug_reportVulnerabilityLastPass breached via Klue supply chain attack; OAuth tokens stolen
LastPass customers. Attack vector: compromised Klue third-party service leading to OAuth token theft and unauthorized access to LastPass Salesforce environment containing customer data.
highperson_alertThreat ActorIcarus Extortion Group Breaches Klue, Steals Salesforce OAuth Tokens
Icarus is an extortion-focused threat actor that has publicly claimed responsibility for breaching the market intelligence platform Klue. The group's motivation appears to be financially driven, targeting SaaS and market intelligence platforms to ste…
highbug_reportVulnerabilitySalesforce disables Klue integration after OAuth token abuse exposes data
Salesforce customers using the Klue Battlecards app integration. OAuth tokens were abused to access customer data. Integration disabled as of June 11, 2026.
highperson_alertThreat ActorIcarus Threat Actor Exploits OAuth to Steal Salesforce Data via Klue
Icarus is a threat actor conducting an ongoing extortion campaign targeting organizations through supply chain compromise. The actor exploited OAuth authentication mechanisms to breach Klue, a market intelligence platform, gaining unauthorized access…