Klue
Supply Chain Attack
Research Framing
| Field | Value | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Decision Question | Did Klue's compromised integration path expose this organization's Salesforce data, and what must downstream customers investigate, contain, and disclose first? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Interpreted Questions | What is Klue? What happened with its Salesforce integration? Why does this create downstream customer exposure? What did LastPass confirm? How should Salesforce, legal, privacy, IR, and vendor-risk teams scope impact? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Initial Observations | Primary vendor and customer notices establish unauthorized activity in Klue's integration infrastructure, token-backed Salesforce access, downstream customer exposure, and different organization-specific data boundaries. They do not establish a Salesforce platform vulnerability or identical impact for every Klue customer. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Evidence Hierarchy | Tier 0 primary vendor, customer, regulator, and law-enforcement material controls confirmed facts and each victim boundary. Technical research and reporting may explain mechanics or corroborate chronology; community, aggregation, discovery, and expansion sources cannot override primary disclosures. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Tier 0 Through Tier 8 Coverage |
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Fact / Analysis / Unknown Boundaries | Fact: retained primary sources describe the integration compromise and the scope publicly confirmed by each named organization. Analysis: defenders should treat the event as a trusted SaaS and cloud-identity supply-chain exposure path. Unknown: any unreported customer's actual object access, data loss, notification duty, or actor linkage remains unconfirmed until supported by that customer's evidence. |
Klue Exposure Snapshot
| Field | Assessment | Sources |
|---|---|---|
| What Klue is | A competitive enablement / market-intelligence SaaS platform used to sync sales battlecards, win/loss context, competitive positioning, and seller guidance with CRM systems such as Salesforce. | 5,6 |
| Why this is supply chain | The exposure flowed through a trusted third-party SaaS integration into downstream customer Salesforce environments, rather than through a direct breach of each customer first. | 1,3,5,6 |
| Reported mechanism | 02-Jul-2026 · Freshly reported (<24h) Klue's CrowdStrike summary says a previously compromised GitHub PAT (personal access token) was used to introduce unauthorized code into the integration service and collect third-party integration credentials, including Salesforce OAuth access and refresh tokens. 31-Jul-2026 · Freshly reported (<24h) Klue's CTO post adds that the attacker first downloaded source code, obtained an additional GitHub PAT, identified and tested credentials, then used a build/deployment path to deploy a tampered production workload that enabled stored OAuth-token access. | 1,5,6,59,75 |
| Not currently framed as | A Salesforce platform vulnerability, a CVE, or proof that every Klue customer experienced the same data exposure. | 1,2,6 |
1-Topic
Klue is a competitive enablement and market-intelligence SaaS platform whose Salesforce integration can sit close to customer and prospect CRM records. The public incident is best framed as a trusted SaaS integration and OAuth-token exposure path, not as a confirmed Salesforce platform vulnerability. 1,2,5,6
The operational question for downstream customers is whether Klue or Klue Battlecards had token-backed access into their Salesforce environment, which objects were reachable, and whether Salesforce API activity indicates customer, prospect, support, or commercial data access. 3,5,6,7,30
Public customer notices now make this a concrete disclosure-pattern issue as well as a technical one: responders should preserve Salesforce logs, revoke and rotate integration tokens, scope CRM objects, and keep product-system compromise language separate from Salesforce business-data exposure. 11,12,32,33,34,35,38,39,40,41,42,43
2-Persona / Audience Lens
This brief is written for CISOs, Salesforce administrators, SaaS owners, SOC/IR teams, breach counsel, privacy teams, client-facing cyber advisors, and vendor-risk leaders. It prioritizes evidence that can be validated quickly: Klue use, Salesforce connected-app state, OAuth/token revocation, CRM API activity, customer-data scoping, and which claims are official versus technically inferred.
3-BLUF
- Klue is a competitive enablement SaaS provider with Salesforce integration paths; the incident matters because attackers can abuse that trusted integration relationship to reach downstream customer CRM data. 1,5,6
- LastPass publicly confirmed a Klue-linked customer-data incident while stating its product systems, services, infrastructure, and vaults were not compromised. 3,4,30
- The strongest technical framing is OAuth/connected-app abuse: compromised Klue integration access produced token-backed Salesforce API activity, not a Salesforce core-platform exploit. 1,2,5,6
- Responder priority is to revoke and rotate Klue/Salesforce integration tokens and credentials, preserve Salesforce logs, scope CRM data queried or exported, and notify legal/privacy teams where customer or prospect data was accessed. 1,5,6,7
- 29-Jun-2026 · Newly retained (>24h) Icarus remains the public actor label tied to the Klue extortion/data-theft activity in this source set. FINRA and ZeroFox reinforce Icarus/ICARUS naming and mitigation priorities, while ZeroFox also notes Underground Uwu / Scattered Lapsus$ Hunters claims that remain caveated. No reliable source merged Klue with UNC6395/Salesloft Drift. 5,6,36,37,53,54
- 30-Jun-2026 · Newly retained (>24h) ControlUp, Deel, and Saviynt add direct public customer-disclosure boundaries for Salesforce/CRM sales or business data exposure. 30-Jun-2026 · Newly retained (publication date not visible)ABBYY adds an undated trust-center boundary. These sources expand public victimology but do not change the Salesforce platform-vulnerability boundary or actor attribution. 55,56,57,58
- 02-Jul-2026 · Freshly reported (<24h) Klue's primary CrowdStrike update revises the mechanism from generic legacy-credential compromise to a GitHub PAT (personal access token) and unauthorized integration-service code path, while stating CrowdStrike found no evidence of threat-actor access outside integration-service-related systems or activity after June 12. 59
- 04-Jul-2026 · Newly retained (publication date not visible) Postman adds a direct public customer-disclosure boundary: Salesforce customer contact and sales information was exfiltrated via the compromised Klue service account, customer data was not accessed from Gong, and Postman core platform services were not impacted. 60
- 05-Jul-2026 · Newly retained (>24h) Automox adds a useful no-impact disclosure boundary: after Klue/Salesforce review, it reported no anomalous or malicious Salesforce activity and said Klue had no indication Automox data or customer data was affected. Treat this as leak-list deconfliction, not a confirmed data-theft victim row. 61
- 07-Jul-2026 · Newly retained (>24h) eSentire adds a narrow direct customer-disclosure boundary: Salesforce data was accessed through Klue, exposure was described as minimal due to restricted OAuth permissions and a limited connected-app footprint, and eSentire reported no identified customer-service risk from the incident. 62
- 08-Jul-2026 · Newly retained (>24h) Thinkproject adds a UAT CRM-specific customer-disclosure boundary: the Klue-linked access involved Salesforce/CRM business-contact and commercial information, while Thinkproject states its products and services were not affected and its CRM system is separate from the customer product platform. 16-Aug-2026 · Newly retained (>24h) Thinkproject's Aug. 12 status resolution adds that its investigation concluded, it is not aware of misuse of the affected data, and monitoring continues. 63
- 09-Jul-2026 · Newly retained (>24h) Snyk now closes its Klue/Salesforce status incident after a Mandiant-assisted forensic investigation, preserving a business-CRM-data-only boundary. 09-Jul-2026 · Freshly reported (<24h) Secure ISS relays a SentinelOne partner-notification boundary: Salesforce-environment-only impact through the Klue API integration, no lateral movement, and no core-product, cloud-infrastructure, or production-environment impact reported. 64,65
- 11-Jul-2026 · Newly retained (>24h) OneTrust's July 10 update closes its technical investigation and narrows the public boundary: containment and remediation are complete, and the independent forensic investigation found no evidence of exposure beyond OneTrust's Salesforce environment. Governance, compliance, and notification review remain ongoing. 44
- 13-Jul-2026 · Freshly reported (<24h) Microsoft places Klue in a broader Salesforce/SaaS OAuth-abuse tradecraft discussion associated with ShinyHunters. 18-Jul-2026 · Newly retained (>24h) Microsoft also names Storm-3138 for the Klue system access path; preserve Icarus/ICARUS as the Klue-specific public extortion/operator label unless stronger evidence merges or replaces that attribution. 66
- 14-Jul-2026 · Newly retained (publication date not visible) Sisense adds another direct public customer-disclosure boundary: Sisense says the Klue incident was limited to certain business and sales-related data in its Salesforce CRM application and did not impact the Sisense product platform or product-platform data. 67
- 16-Jul-2026 · Newly retained (>24h) Qualtrics and Splashtop add older direct public customer-disclosure boundaries: both tie Klue to Salesforce access and preserve product/platform exclusions, while Splashtop notes its investigation remained ongoing. 68,69
- 23-Jul-2026 · Newly retained (>24h) Greenhouse and Blackbaud add direct Conveyor trust-center disclosure boundaries. Greenhouse limits accessible data to business contact information in sales/customer relationship systems and excludes product, hiring, candidate, infrastructure, modification, and deletion impact. Blackbaud states its investigation remains ongoing with no substantive update, no known Blackbaud product impact, and no business-operations/customer-service impact. 70,71
- 24-Jul-2026 · Newly retained (publication date not visible) Confluent adds another direct trust-center boundary: copied data was limited to Confluent business information in its CRM system, while Confluent states product-processed customer data was not involved or impacted and that there is no indication its products, platform, or infrastructure were affected. 72
- 28-Jul-2026 · Newly retained (>24h) Autodesk adds a direct no-impact deconfliction boundary: it says Klue notified Autodesk on June 16, Autodesk did not use the Salesforce or Gong integrations for Klue, and Autodesk identified no direct impact to Autodesk products, services, or systems. 73
- 30-Jul-2026 · Newly retained (>24h) Klue adds a primary restoration milestone: Salesforce and Gong reinstated Klue integrations in their marketplaces, all Klue integrations are available for customer re-enablement, and Klue says restoration followed CrowdStrike review plus controls for static egress IPs, platform-wide PKCE, OAuth-token lifecycle tightening, GitHub PAT elimination, centralized monitoring, runtime network filtering, and deployment-pipeline allowlisting. 74
- 31-Jul-2026 · Freshly reported (<24h) Klue's CTO adds a primary engineering lesson learned: treat GitHub and CI/CD as part of the production security boundary, reduce long-lived credential reliance, bind remaining credentials to workload, identity, network context, and least privilege, and review OAuth scopes with the authorizing account's effective privileges. 75
- 02-Aug-2026 · Newly retained; undated Yext adds a direct undated SafeBase disclosure boundary: read-only queries hit Yext's internal Salesforce CRM for roughly 17 hours on June 11-12 through stolen Klue-held credentials, exposing business contact details for customers and prospects while excluding Yext platform, product, infrastructure, customer-content, customer-facing-system, end-user-data, payment-card, Google Workspace, and Slack impact. 76
- 03-Aug-2026 · Newly retained (>24h) Commvault and NetDocuments add two older rendered public disclosure boundaries. Commvault limits accessed data to Salesforce business relationship and sales activity information while excluding customer data, solutions/services, customer backup data, product metadata, and logs. NetDocuments says Klue impact was limited to internal Gong-user staff-list data and excludes customer data, prospective customer data, Customer Repository Data, and NetDocuments Service impact. 77,78
- 04-Aug-2026 · Newly retained (>24h) Neon One adds a direct public notice-letter boundary: a Klue incident involving Neon One's Salesforce CRM integration service resulted in unauthorized access to some personal information between June 11-12; Neon One says the incident was contained and no further impact was identified. 79
- 10-Aug-2026 · Newly retained (>24h) Betterment adds a regulator-hosted public notice-letter boundary: the Mass.gov PDF says Klue Labs Inc. was a vendor used by Betterment's sales team and had access to a Salesforce database containing Betterment data. 11-Aug-2026 · Newly retained (>24h) PDF text re-review clarifies that the accessed file contained name and Social Security number, Betterment's computer systems were not accessed, and two years of Kroll identity monitoring were offered. Do not infer Betterment product-system, brokerage, bank, account-access, or credential compromise from the notice. 80
4-Executive Summary
Klue is a competitive enablement and market-intelligence SaaS platform used by sales teams to synchronize battlecards, win/loss context, and competitive intelligence with CRM workflows. That business role matters: a Klue integration can sit close to sensitive Salesforce data such as accounts, contacts, leads, opportunities, notes, and customer relationship context. Public reporting and Klue's own statement describe unauthorized activity affecting part of Klue's integration infrastructure, with a compromised legacy integration credential used to obtain OAuth tokens that connected Klue to Salesforce. 02-Jul-2026 · Freshly reported (<24h) Klue's later CrowdStrike summary refines that mechanism: a previously compromised GitHub PAT was used to introduce unauthorized code into Klue's integration service and collect third-party integration credentials, including Salesforce OAuth access and refresh tokens. 1,5,6,59
This is a supply-chain attack because downstream customers may be exposed through a trusted third-party application rather than through a direct compromise of their own infrastructure first. LastPass publicly confirmed a Klue-linked customer-data incident and said its LastPass product systems and vaults were not compromised. That distinction is important for executives and counsel: the event may still trigger CRM data, privacy, and notification analysis even where core product systems, password vaults, or endpoint infrastructure were not breached. 3,4
26-Jun-2026 · Newly retained (>24h) LastPass's detailed response adds useful scoping language for counsel and customer communications: the company describes Salesforce and Gong integration context, token rotation, discontinued Klue access, law-enforcement cooperation, customer anti-phishing guidance, published IOCs, and a product/vault boundary. 30 26-Jun-2026 · Freshly reported (<24h) TechCrunch adds a second-wave extortion concern: Klue reportedly told customers the original criminals were deleting stolen data while another group had begun making threats. 31
26-Jun-2026 · Freshly reported (<24h) SecurityWeek now reports roughly two dozen public Klue-Salesforce impact disclosures and names an expanded set of customer-notice examples. 36 26-Jun-2026 · Newly retained (>24h) Obsidian adds tenant-forensics detail across impacted organizations, including Global Describe reconnaissance, QueryMore pagination, API-version deviation, user-agent deviation, and broad object harvest patterns. 37
27-Jun-2026 · Newly retained (>24h) LogicMonitor/Catchpoint and Tanium add direct customer-disclosure boundaries: both tie the incident to Salesforce data exposure through Klue while separating that exposure from core product, production, monitoring, or cloud-infrastructure compromise. 41,43 27-Jun-2026 · Newly retained (publication date not visible) Tines adds a trust-center boundary that Klue credentials were used to access Salesforce data, with no evidence of unauthorized access to the Tines platform or customer environments. 42
28-Jun-2026 · Newly retained (>24h) OneTrust, Gong, and Insurity add three direct public-disclosure boundaries: OneTrust ties the event to Klue Battlecards/Salesforce CRM-related data without evidence of customer-tenant exposure; Gong scopes impact to customers who connected Klue with Gong and says call recordings/transcripts were not directly impacted; Insurity says a limited set of active credentials found in exposed CRM data were rotated or reset and that Insurity products were not involved. 44,45,46
29-Jun-2026 · Freshly reported (<24h) AudienceView adds a fresh status-page resolution timestamp while retaining the older June 22 monitoring context for its Klue-Salesforce integration incident. 47 29-Jun-2026 · Newly retained (>24h) Link11 adds a direct CRM-data notice, while FINRA and ZeroFox add sector guidance, Icarus/ICARUS reinforcement, limited IOCs, and a caveat that Underground Uwu / Scattered Lapsus$ Hunters claims should not be collapsed into UNC6395/Salesloft Drift. 48,53,54 29-Jun-2026 · Newly retained (publication date not visible) AlertMedia, Cresta, and Lucanet add undated trust-center disclosures that improve public victim boundary coverage without creating a universal impact model; Camunda is now handled separately because its latest trust-center update provides a dated source-specific boundary revision. 49,50,51,52
30-Jun-2026 · Newly retained (>24h) ControlUp, Deel, and Saviynt add direct public customer-disclosure boundaries for Klue-linked Salesforce, CRM, sales, or business-contact data exposure while separating that exposure from their respective product, production, infrastructure, or product-customer-data environments. 55,56,57 30-Jun-2026 · Newly retained (publication date not visible) ABBYY adds an undated trust-center disclosure stating Salesforce data accessed through Klue's integration was affected while ABBYY's network, products, and technology were not affected. 58
04-Aug-2026 · Newly retained (>24h) Neon One adds a direct public notice-letter boundary: Klue provided an integration service for Neon One's Salesforce customer relationship management software, and the Klue incident resulted in unauthorized access to some personal information between June 11 and June 12. Neon One says the incident was contained and no further impact was identified. 79
02-Jul-2026 · Freshly reported (<24h) Klue says CrowdStrike completed its investigation on June 30, found no evidence of threat-actor access outside systems related to the integration service, found no evidence of threat-actor activity in the Klue environment after June 12, and that Klue deployed CrowdStrike Falcon monitoring. 59 02-Jul-2026 · Newly retained (>24h) Camunda's latest trust-center update narrows Camunda's own impact boundary: exfiltrated data did not include support data and was limited to standard business-contact and account information in Salesforce CRM. 50
04-Jul-2026 · Newly retained (publication date not visible) Postman's Security & Trust Portal adds a direct public customer-disclosure boundary: Postman says customer contact data and sales information were exfiltrated from its Salesforce environment via the compromised Klue service account between June 11-12, customer data was not accessed from Gong, and Postman's core platform services remain secure and were not impacted. 60
07-Jul-2026 · Newly retained (>24h) eSentire adds another direct public customer-disclosure boundary: eSentire says it uses Klue, was among the organizations whose Salesforce data was accessed, and describes the exposure as minimal because the integration was tightly scoped with restricted OAuth permissions and a limited connected-app footprint. It reports no identified risk to customers from eSentire's services and excludes customer communications, support interactions, threat intelligence, telemetry, credentials, passwords, and payment-card data. 62
08-Jul-2026 · Newly retained (>24h) Thinkproject adds a UAT CRM-specific public customer boundary: Klue had authorized software-integration access to that CRM environment, exfiltrated data may include business-contact and commercial information, Thinkproject products and services were not affected, and the CRM system is separate from the customer product platform. 63
09-Jul-2026 · Newly retained (>24h) Snyk's July 8 status resolution adds investigation-closure confidence: Snyk says its Klue/Salesforce forensic investigation, conducted with Mandiant, is complete; the impact remained limited to business CRM data; and no Snyk platform or sensitive platform-data impact was found. 64 09-Jul-2026 · Freshly reported (<24h) Secure ISS's July 9 advisory relays a SentinelOne partner-notification boundary: the Klue impact was contained to SentinelOne's Salesforce environment through the Klue API integration, with no lateral movement and no core-product, cloud-infrastructure, or production-environment impact reported. Treat it as a qualified public advisory because the direct SentinelOne portal reference is access-controlled and data analysis remains ongoing. 65
11-Jul-2026 · Newly retained (>24h) OneTrust's July 10 update closes its technical investigation, validates scope, and finalizes containment and remediation. OneTrust says the independent forensic investigation found no evidence of exposure beyond its Salesforce environment, while governance, compliance, and notification review remain ongoing. 44
13-Jul-2026 · Freshly reported (<24h) Microsoft's July 13 research adds a fresh campaign-deconfliction layer: it groups Salesforce and SaaS OAuth-abuse activity observed from mid-2025 to mid-2026 as tradecraft commonly associated with ShinyHunters and includes Klue integration activity in that broader discussion. 18-Jul-2026 · Newly retained (>24h) Microsoft also names Storm-3138 for the Klue system-access path. Use this to strengthen OAuth/connected-app hunting and activity-cluster deconfliction while preserving Icarus/ICARUS as the Klue-specific public extortion/operator label unless a reliable source directly merges or replaces that attribution. 66
14-Jul-2026 · Newly retained (publication date not visible) Sisense adds another direct public customer-disclosure boundary: its Trust Center says Sisense was one of many affected organizations and that the incident was limited to certain business and sales-related data in Sisense's Salesforce CRM application. Sisense states the product platform and data stored within the product platform were not impacted, and says it disconnected certain third-party integrations, rotated credentials and tokens to Klue and Salesforce, and is monitoring access logs. 67
16-Jul-2026 · Newly retained (>24h) Qualtrics and Splashtop add two older direct public disclosure boundaries. Qualtrics says the Klue application connected to Salesforce for internal sales-team support, unauthorized access was limited to a subset of Salesforce data, impacted data included business-to-business identifiers, and Qualtrics products, core infrastructure, services, and hosted platform customer data were not accessed or compromised. Splashtop says Klue OAuth tokens were used to access certain Salesforce data, it disabled the Klue Salesforce integration and revoked access, the investigation remained ongoing, and Splashtop products and services were not impacted. 68,69
23-Jul-2026 · Newly retained (>24h) Greenhouse and Blackbaud add direct Conveyor trust-center boundaries. Greenhouse says attackers obtained Klue credentials used to connect to certain Greenhouse business systems; access occurred on June 11, was scoped to Klue's integration, did not involve Greenhouse infrastructure, and was limited to business contact information in sales/customer relationship systems. Blackbaud's July 22 update says its investigation remains ongoing with no substantive update, no known impact to Blackbaud products, and no impact to business operations or customer-service ability. 70,71
30-Jul-2026 · Newly retained (>24h) Klue's July 27 restoration update changes the operational posture from disabled integrations only to controlled re-enablement. Klue says Salesforce and Gong reinstated Klue integrations in their marketplaces, all Klue integrations are again available for customers to enable, and Klue added controls including static egress IPs allow-listed by Salesforce and Gong, platform-wide PKCE, tightened OAuth token lifecycle policies, elimination of GitHub personal access tokens, centralized monitoring and detection, runtime network filtering, and deployment-pipeline allowlisting. 74
31-Jul-2026 · Freshly reported (<24h) Klue's CTO post adds the freshest primary engineering detail: the intrusion unfolded from GitHub PAT access into source-code download, additional PAT discovery, credential testing, build/deployment-path abuse, and a tampered production workload that enabled stored OAuth-token access. It reinforces CI/CD as a production security boundary and calls out durable controls around GitHub Apps or workload identity, default-deny network controls, refresh-token rotation or idle expiration, IP-range allow-listing, and low-privilege integration accounts where supported. 75
02-Aug-2026 · Newly retained; undated Yext adds a direct SafeBase trust-center boundary: Yext says stolen Klue-held credentials were used to run read-only queries against Yext's internal Salesforce CRM for roughly 17 hours on June 11-12, exposing business contact details for customers and prospects. Yext excludes platform, product, infrastructure, customer-content, customer-facing-system, end-user-data, payment-card, Google Workspace, and Slack impact. 76
03-Aug-2026 · Newly retained (>24h) Commvault and NetDocuments add older rendered public disclosure boundaries that improve customer-impact scoping without changing the upstream Klue/Salesforce OAuth mechanism. Commvault limits accessed data to Salesforce business relationship and sales activity information and excludes customer data, Commvault solutions/services, customer backup data, product metadata, and logs. NetDocuments says the NetDocuments Service was not impacted and limits the Klue-related impact to internal Gong-user staff-list data, while excluding customer data, prospective customer data, and Customer Repository Data. 77,78
The best technical framing is OAuth/connected-app abuse in the Salesforce ecosystem. Klue says it revoked credentials and tokens, removed unauthorized code, disabled potentially impacted integrations, and notified law enforcement. ReliaQuest and Datadog add the operational layer: token-backed access, automated Salesforce REST API queries, OAuth refresh-token evidence, connected-app identification, and object-level scoping are the artifacts defenders should examine. 1,5,6
For responders, the first question is not "did we patch Salesforce?" It is "did we use Klue or Klue Battlecards, what Salesforce data did that integration reach, and did token-backed API activity occur in our tenant?" The near-term response is to preserve Salesforce logs, identify Klue connected apps, revoke and rotate tokens and integration secrets, scope CRM objects queried or exported, and coordinate legal, privacy, and client communications around confirmed data access rather than speculative actor claims.
The closest public comparator is the Salesloft Drift campaign: Google Cloud, FBI/IC3, Unit 42, Arctic Wolf, BleepingComputer, and FINRA all describe a trusted SaaS integration/OAuth-token path into downstream Salesforce environments. That prior campaign is why Klue should be scoped as a SaaS integration supply-chain event, not as an isolated vendor notice. 18,19,20,21,22,24
5-AI Agent Delta Updates
| Run / Schedule | Delta Status | Monitoring Scope | Next Action |
|---|---|---|---|
26-Jun-2026 · Monitoring setup Bootstrap run: 26-Jun-2026 9:08 AM ET | Source-backed bootstrap deltas incorporated. Added one freshly reported follow-on extortion source, newly retained customer/impact notices, and a primary LastPass response page with additional response and boundary detail. | Klue, LastPass, Salesforce, Huntress, Datadog, ReliaQuest, BleepingComputer, customer notices, public victim/disclosure updates, associated campaign names, OAuth/Salesforce forensic guidance, and Salesloft Drift comparator changes. | Daily monitor at 1:30 AM ET for 12 months. Notify configured active subscribers after every run, including no-change checks. |
26-Jun-2026 · Monitor run Run: 26-Jun-2026 9:31 PM ET | Source-backed deltas incorporated. Freshly reported (<24h): SecurityWeek, published 26-Jun-2026 11:01 AM ET. Newly retained (>24h): Obsidian, Pendo, and 8x8. Newly retained (publication date not visible): Recorded Future. | Searched Klue/Salesforce OAuth abuse, LastPass, Huntress, Datadog, ReliaQuest, SecurityWeek, public victim notices, Icarus/UNC6395 campaign naming, and Salesloft Drift comparator reporting. Public-victim/disclosure search found additional named disclosure examples. Associated-campaign search reinforced Icarus as the Klue label; no reliable source merged Klue with UNC6395. | Next scheduled monitor: 27-Jun-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, new customer notices, and verified campaign-attribution changes. |
27-Jun-2026 · Monitor run Run: 27-Jun-2026 9:33 PM ET | Source-backed deltas incorporated. Newly retained (>24h): LogicMonitor/Catchpoint, published 26-Jun-2026, and Tanium, published 18-Jun-2026. Newly retained (publication date not visible): Tines Trust Center. No Freshly reported (<24h) source was retained in this run. | Searched Klue/Salesforce OAuth abuse, LastPass, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, customer notices, public victim disclosures, Icarus/UNC6395 campaign naming, and Salesloft Drift comparator reporting. Public-victim/disclosure search found additional direct customer notices. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. | Next scheduled monitor: 28-Jun-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, new customer notices, and verified campaign-attribution changes. |
28-Jun-2026 · Monitor run Run: 28-Jun-2026 9:31 PM ET | Source-backed deltas incorporated. Newly retained (>24h): OneTrust, published 24-Jun-2026; Gong, published 19-Jun-2026; and Insurity Status, published 18-Jun-2026 and updated 22-Jun-2026. No Freshly reported (<24h) source was retained in this run. | Searched Klue/Salesforce OAuth abuse, Klue Battlecards, LastPass, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Salesforce status/trust updates, direct customer notices, named public victim disclosures, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, and Salesloft Drift comparator reporting. Public-victim/disclosure search found additional direct OneTrust, Gong, and Insurity notices. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. | Next scheduled monitor: 29-Jun-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, new customer notices, and verified campaign-attribution changes. |
29-Jun-2026 · Monitor run Run: 29-Jun-2026 9:31 PM ET | Source-backed deltas incorporated. Freshly reported (<24h): AudienceView status resolution, published/resolved 29-Jun-2026 with an initial 22-Jun-2026 monitoring record. Newly retained (>24h): Link11, FINRA, and ZeroFox. Newly retained (publication date not visible): AlertMedia, Camunda, Cresta, and Lucanet trust-center notices. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, public victim notices, Salesforce trust/status updates, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found additional direct notices. Associated-campaign/activity-cluster search reinforced Icarus/ICARUS and Underground Uwu/SLH caveats; no reliable source merged Klue with UNC6395/Salesloft Drift. | Next scheduled monitor: 30-Jun-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, new customer notices, and verified campaign-attribution changes. |
30-Jun-2026 · Monitor run Run: 30-Jun-2026 9:31 PM ET | Source-backed deltas incorporated. Newly retained (>24h): ControlUp, published 26-Jun-2026; Deel, published 25-Jun-2026 and last updated 26-Jun-2026; and Saviynt, published 23-Jun-2026. Newly retained (publication date not visible): ABBYY Trust Center. No Freshly reported (<24h) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Salesforce status/trust updates, public victim/customer notices, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found additional direct notices. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. | Next scheduled monitor: 01-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, new customer notices, and verified campaign-attribution changes. |
01-Jul-2026 · Monitor run Run: 01-Jul-2026 9:31 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Salesforce status/trust updates, public victim/customer notices, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. | Next scheduled monitor: 02-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, new customer notices, and verified campaign-attribution changes. |
02-Jul-2026 · Monitor run Run: 02-Jul-2026 9:31 PM ET | Source-backed deltas incorporated. Freshly reported (<24h): Klue CrowdStrike Investigation Summary and Security Improvements, schema published 02-Jul-2026 12:02 AM ET with a visible 01-Jul-2026 byline. Newly retained (>24h): Camunda Trust Center 01-Jul-2026 investigation update narrowing its support-data boundary. Newly retained (publication date not visible): none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Salesforce status/trust updates, public victim/customer notices, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found a source-backed Camunda boundary revision but no new named victim requiring a new row. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. | Next scheduled monitor: 03-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, new customer notices, and verified campaign-attribution changes. |
04-Jul-2026 · Monitor run Run: 04-Jul-2026 9:31 PM ET | Source-backed deltas incorporated. Newly retained (publication date not visible): Postman Security & Trust Portal Notice of Security Incident, retrieved 04-Jul-2026 9:31 PM ET. No Freshly reported (<24h) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Salesforce status/trust updates, direct customer notices, public victim disclosures, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found Postman's direct customer notice and rejected duplicative SEO rewrites, leak-site-only claims, and inaccessible/truncated trust-center leads without enough boundary detail. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. | Next scheduled monitor: 05-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, new customer notices, and verified campaign-attribution changes. |
05-Jul-2026 · Monitor run Run: 05-Jul-2026 9:31 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed deltas incorporated. Newly retained (>24h): Automox Trust Center Klue Security Incident, published 29-Jun-2026 and retrieved 05-Jul-2026 9:31 PM ET. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Salesforce status/trust updates, direct customer notices, public victim disclosures, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found Automox's direct no-impact trust-center notice and did not promote NetDocuments search-index-only text, duplicative SEO rewrites, social posts, leak-site-only claims, or unsupported speculation. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. | Next scheduled monitor: 06-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. |
06-Jul-2026 · Monitor run Run: 06-Jul-2026 9:31 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Salesforce status/trust updates, affected-customer notices, public victim disclosures, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. | Next scheduled monitor: 07-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. |
07-Jul-2026 · Monitor run Run: 07-Jul-2026 9:32 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed deltas incorporated. Newly retained (>24h): eSentire Responding to the Klue Incident, published 26-Jun-2026 and retrieved 07-Jul-2026 9:32 PM ET. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Salesforce status/trust updates, affected-customer notices, public victim disclosures, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found eSentire's direct customer disclosure and did not promote NetDocuments sparse/search-index-only text, generic Salesforce OAuth recaps, LinkedIn/social posts, leak-site-only claims, or duplicate media rewrites. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. | Next scheduled monitor: 08-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. |
08-Jul-2026 · Monitor run Run: 08-Jul-2026 9:32 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed deltas incorporated. Newly retained (>24h): Thinkproject Status Klue Breach that Allowed Data Exfiltration from Salesforce, published 26-Jun-2026 6:47 AM and retrieved 08-Jul-2026 9:32 PM ET. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Salesforce status/trust updates, affected-customer notices, public victim disclosures, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found Thinkproject's direct status notice and did not promote duplicative summaries, generic Salesforce OAuth recaps, LinkedIn/social posts, leak-site-only claims, sparse status aggregators, or duplicate media rewrites. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. | Next scheduled monitor: 09-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. |
09-Jul-2026 · Monitor run Run: 09-Jul-2026 9:31 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed deltas incorporated. Newly retained (>24h): Snyk Status Third-Party Vendor Security Incident (Klue), resolved 08-Jul-2026 11:26 AM ET and retrieved 09-Jul-2026 9:31 PM ET. Freshly reported (<24h): Secure ISS SentinelOne Klue advisory, published 09-Jul-2026 and retrieved 09-Jul-2026 9:31 PM ET. Newly retained (publication date not visible): none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found Snyk's investigation-closure notice and a qualified SentinelOne public advisory/partner-notification lead; it rejected NetDocuments JavaScript-only/search-index text, duplicative SEO recaps, generic OAuth commentary, leak-site-only claims, and unsupported Salesforce/OAuth attribution rewrites. | Next scheduled monitor: 10-Jul-2026 1:30 AM ET. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. |
10-Jul-2026 · Monitor run Run: 10-Jul-2026 9:32 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; NetDocuments remained JavaScript-only/search-index text without a stable inspectable disclosure body. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 11-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. |
11-Jul-2026 · Monitor run Run: 11-Jul-2026 9:31 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed customer-boundary delta incorporated. Newly retained (>24h): OneTrust Update From OneTrust on Klue Security Incident, updated 10-Jul-2026 and retrieved 11-Jul-2026 9:31 PM ET. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found OneTrust's July 10 investigation-complete boundary update and rejected duplicate media recaps, social posts, leak-site-only claims, generic OAuth/Salesforce commentary, and unsupported Klue/Salesloft Drift conflation. | Next scheduled monitor: 12-Jul-2026 1:30 AM ET. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. |
12-Jul-2026 · Monitor run Run: 12-Jul-2026 9:31 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, Icarus, UNC6395, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 13-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. |
13-Jul-2026 · Monitor run Run: 13-Jul-2026 9:31 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed campaign-deconfliction delta incorporated. Freshly reported (<24h): Microsoft Security Research / Microsoft Defender Security Research Team, published 13-Jul-2026 and retrieved 13-Jul-2026 9:31 PM ET. Newly retained (>24h): none. Newly retained (publication date not visible): none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable named organization notice that changed the brief. Associated-campaign/activity-cluster search found Microsoft ShinyHunters-associated OAuth-abuse research that improves deconfliction but does not merge Klue/Icarus with UNC6395 or Salesloft Drift. | Next scheduled monitor: 14-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. |
14-Jul-2026 · Monitor run Run: 14-Jul-2026 9:32 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed public customer-disclosure delta incorporated. Newly retained (publication date not visible): Sisense Trust Center Security Update: Klue Security Incident, retrieved 14-Jul-2026 9:32 PM ET. No Freshly reported (<24h) or Newly retained (>24h) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found Sisense's direct trust-center notice and rejected duplicate media recaps, SEO rewrites, leak-site-only claims, JavaScript-only NetDocuments text, generic Salesforce/OAuth commentary, and unsupported Klue/Salesloft Drift conflation. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 15-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. |
15-Jul-2026 · Monitor run Run: 15-Jul-2026 9:31 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; NetDocuments and Commvault trust-center pages remained JavaScript-only or unavailable to stable public inspection. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. Microsoft and RH-ISAC/TechRadar ShinyHunters OAuth coverage was already represented by the retained Microsoft source and was not promoted as a duplicate delta. | Next scheduled monitor: 16-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. |
16-Jul-2026 · Monitor run Run: 16-Jul-2026 9:32 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed public customer-disclosure deltas incorporated. Newly retained (>24h): Qualtrics XM Trust Center Klue Supply Chain Compromise response, published 25-Jun-2026 12:55 UTC and retrieved 16-Jul-2026 9:32 PM ET; Splashtop Security Update Regarding Third-Party Klue Incident, updated 30-Jun-2026 and retrieved 16-Jul-2026 9:32 PM ET. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found Qualtrics and Splashtop direct notices and rejected duplicate media recaps, VenariX aggregated victim tracking, NetDocuments and Commvault JavaScript-only trust-center shells without stable inspectable bodies, leak-site-only claims, generic Salesforce/OAuth commentary, and unsupported Klue/Salesloft Drift conflation. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 17-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. |
18-Jul-2026 · Monitor run Run: 18-Jul-2026 9:31 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed campaign/activity-label clarification incorporated. Newly retained (>24h): existing Microsoft Security Research / Microsoft Defender Security Research Team source, published 13-Jul-2026 and re-reviewed 18-Jul-2026 9:31 PM ET, now explicitly retained for the Storm-3138 Klue system-access label. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the victim matrix; Commvault remained a JavaScript-only trust-center shell without a stable inspectable body. Associated-campaign/activity-cluster search found Microsoft's Storm-3138 label already present in the retained Microsoft source and promoted it as a deconflicted activity-label clarification, not an actor merger. | Next scheduled monitor: 19-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. |
19-Jul-2026 · Monitor run Run: 19-Jul-2026 9:32 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the victim matrix; Commvault remained a JavaScript-only Vanta trust-center shell without a stable inspectable disclosure body. Insurity's July 9 status update remained represented by the retained Insurity citation and did not change the brief. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 20-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
20-Jul-2026 · Monitor run Run: 20-Jul-2026 9:32 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the victim matrix; Sprout Social, Jamf, LastPass, Huntress, Tanium, Recorded Future, Insurity, and other retained notices remained represented by existing citations and boundaries. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Nudge Security, TechRadar, The Hacker News, SecurityBoulevard, and other recent or recrawled summaries were treated as duplicate or secondary coverage and not promoted. | Next scheduled monitor: 21-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
21-Jul-2026 · Monitor run Run: 21-Jul-2026 9:32 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the victim matrix; Commvault remained a JavaScript-only Vanta trust-center shell without a stable inspectable disclosure body, and VenariX aggregated victim tracking remained insufficient for organization-specific impact-boundary rows without direct public notices. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 22-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
22-Jul-2026 · Monitor run Run: 22-Jul-2026 9:31 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the victim matrix; Commvault remained a JavaScript-only Vanta trust-center shell without a stable inspectable disclosure body despite current search snippets, and VenariX aggregated victim tracking remained insufficient for organization-specific impact-boundary rows without direct public notices. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Microsoft and The Hacker News ShinyHunters/OAuth coverage remained represented by the existing retained Microsoft source and was not promoted as a duplicate delta. | Next scheduled monitor: 23-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
23-Jul-2026 · Monitor run Run: 23-Jul-2026 9:31 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed direct customer-disclosure deltas incorporated. Newly retained (>24h): Greenhouse Software Trust Center Response to Klue Third-Party Security Incident, published/sent 24-Jun-2026 8:55 AM ET and retrieved 23-Jul-2026 9:31 PM ET; Blackbaud Trust Center Klue Security Incident Update, published 22-Jul-2026 4:05 PM ET and retrieved 23-Jul-2026 9:31 PM ET. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Commvault/NetDocuments/Blackbaud/Confluent/Greenhouse leads, VenariX aggregator tracking, and Salesloft Drift comparator updates. Public-victim/disclosure search found inspectable direct Greenhouse and Blackbaud Conveyor trust-center notices; it did not promote Commvault/NetDocuments JavaScript-only shells, VenariX aggregator-only victim tracking without direct organization-specific public bodies, duplicate media/SEO rewrites, leak-site-only claims, or generic OAuth commentary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 24-Jul-2026 1:30 AM ET. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
24-Jul-2026 · Monitor run Run: 24-Jul-2026 9:31 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed direct customer-disclosure delta incorporated. Newly retained (publication date not visible): Confluent Trust Center Klue Security Incident - Confluent Statement, retrieved 24-Jul-2026 9:31 PM ET. No Freshly reported (<24h) or Newly retained (>24h) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Commvault/NetDocuments/Blackbaud/Confluent/Greenhouse/Pendo/Camunda leads, VenariX aggregator tracking, and Salesloft Drift comparator updates. Public-victim/disclosure search found an inspectable direct Confluent SafeBase trust-center notice; it did not promote Commvault/NetDocuments JavaScript-only shells, duplicate/SEO recaps, leak-site-only claims, generic OAuth commentary, or unsupported Klue/Salesloft Drift conflation. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 25-Jul-2026 1:30 AM ET. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
25-Jul-2026 · Monitor run Run: 25-Jul-2026 9:31 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Commvault/NetDocuments/Blackbaud/Confluent/Greenhouse/Pendo/Camunda leads, VenariX aggregator tracking, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Confluent remained represented by the retained direct SafeBase notice, while VenariX, Tech Insider, ThreatLocker, Field Effect, SecurityBoulevard, Rescana, Nudge Security, QuoIntelligence, and other recent/recrawled summaries were duplicate, aggregate, or generic coverage. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 26-Jul-2026 1:30 AM ET. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
26-Jul-2026 · Monitor run Run: 26-Jul-2026 9:31 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Commvault/NetDocuments/Blackbaud/Confluent/Greenhouse/Pendo/Camunda leads, VenariX aggregator tracking, Microsoft ShinyHunters OAuth coverage, Obsidian update checks, Tech Insider/ThreatLocker/Field Effect/Rescana/Nudge Security/Secure.com recap checks, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Commvault remained a JavaScript-only Vanta trust-center shell on direct retrieval despite current search snippets, NetDocuments remained unavailable to stable public inspection, Confluent remained represented by the retained direct SafeBase notice, and recent/recrawled summaries were duplicate, aggregate, generic, or non-organization-specific coverage. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 27-Jul-2026 1:30 AM ET. PANDA index date remained Updated Jul 26, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
27-Jul-2026 · Monitor run Run: 27-Jul-2026 9:30 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Commvault/NetDocuments/Blackbaud/Confluent/Greenhouse/Pendo/Camunda/Cresta/Lucanet leads, VenariX aggregator tracking, Microsoft ShinyHunters OAuth coverage, LastPass July 23 response URL, Tech Insider/Scrutex/Field Effect/Rescana/Nudge Security/Beazley recap checks, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; LastPass remained represented by the retained direct LastPass response citation, Commvault still lacked a stable inspectable public body on direct retrieval despite search snippets, NetDocuments remained JavaScript-only/unavailable to stable public inspection, and recent/recrawled summaries were duplicate, aggregate, generic, or non-organization-specific coverage. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 28-Jul-2026 1:30 AM ET. PANDA index date updated to Updated Jul 27, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
28-Jul-2026 · Monitor run Run: 28-Jul-2026 9:32 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed direct no-impact disclosure delta incorporated. Newly retained (>24h): Autodesk Trust Center Bulletin: Important Security Notice Regarding Klue, published 23-Jun-2026 and retrieved 28-Jul-2026 9:32 PM ET. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Autodesk/BeyondTrust/Insurity/OneTrust/Commvault/NetDocuments/Confluent leads, VenariX aggregator tracking, Microsoft ShinyHunters OAuth coverage, BankInfoSecurity/TechRadar/Softonic/Field Effect/Beazley/Zscaler/Kudelski recap checks, and Salesloft Drift comparator updates. Public-victim/disclosure search found Autodesk's direct no-impact advisory and rejected duplicate/SEO recaps, generic OAuth commentary, leak-site-only claims, social posts, JavaScript-only status shells without stable bodies, and aggregator victim tracking without organization-specific public notice bodies. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 29-Jul-2026 1:30 AM ET. PANDA index date updated to Updated Jul 28, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
29-Jul-2026 · Monitor run Run: 29-Jul-2026 9:31 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Autodesk/BeyondTrust/Insurity/OneTrust/Commvault/NetDocuments/Confluent/Snyk/Pendo/Camunda/Saviynt/Jamf leads, Commvault and NetDocuments trust-center retrieval checks, NHIMG/kluebreach.com/Vectra/TechRadar/Softonic/Field Effect/Zscaler/Kudelski/Rescana/ThreatLocker recap checks, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Commvault and NetDocuments remained JavaScript-only or empty on direct retrieval despite current search snippets, retained direct notices continued to control each organization's boundary, and duplicate/SEO/aggregate/generic commentary was not promoted. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 30-Jul-2026 1:30 AM ET. PANDA index date updated to Updated Jul 29, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
30-Jul-2026 · Monitor run Run: 30-Jul-2026 9:32 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed primary restoration delta incorporated. Newly retained (>24h): Klue Integrations Restored: Salesforce and Gong Reconnected, published 27-Jul-2026 and retrieved 30-Jul-2026 9:32 PM ET. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Klue Salesforce/Gong restoration, Autodesk/BeyondTrust/Insurity/OneTrust/Commvault/NetDocuments/Confluent/Snyk/Pendo/Camunda/Saviynt/Jamf leads, CSA ShinyHunters OAuth research note, Commvault and NetDocuments trust-center retrieval checks, Osano/Softonic/Hard2bit/BlackFlag/TechRadar/Field Effect/Rescana/ThreatLocker recap checks, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice requiring a victim-matrix change; retained direct notices continue to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision; CSA's July 16 note was treated as secondary/duplicative of already retained Microsoft and primary-source deconfliction. | Next scheduled monitor: 31-Jul-2026 1:30 AM ET. PANDA index date updated to Updated Jul 30, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
31-Jul-2026 · Monitor run Run: 31-Jul-2026 9:32 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed primary engineering delta incorporated. Freshly reported (<24h): Klue What a Security Incident Taught Us About Securing a Modern SaaS Platform, published 31-Jul-2026 6:50 PM ET and retrieved 31-Jul-2026 9:32 PM ET. Klue's July 27 restoration post was also observed with a 31-Jul-2026 6:51 PM ET modification timestamp. No Newly retained (>24h) or Newly retained (publication date not visible) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Klue Salesforce/Gong restoration and CTO lessons-learned posts, Autodesk/BeyondTrust/Insurity/OneTrust/Commvault/NetDocuments/Confluent/Snyk/Pendo/Camunda/Saviynt/Jamf leads, Commvault and NetDocuments trust-center retrieval checks, SecurityBoulevard/CybersecurityNews/NHIMG/Rescana/Hard2bit/TechRadar/BankInfoSecurity/ThreatLocker recap checks, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice requiring a victim-matrix change; Commvault and NetDocuments remained JavaScript-only trust-center shells without stable public disclosure bodies, and retained direct notices continue to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 01-Aug-2026 1:30 AM ET. PANDA index date updated to Updated Jul 31, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
01-Aug-2026 · Monitor run Run: 01-Aug-2026 9:32 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Klue Salesforce/Gong restoration and CTO lessons-learned posts, Insurity/Autodesk/BeyondTrust/OneTrust/Commvault/NetDocuments/Confluent/Snyk/Pendo/Camunda/Saviynt/Jamf leads, RH-ISAC/CSA/The Hacker News/CSO/BankInfoSecurity/Softonic/Nudge Security/Field Effect/ThreatLocker/Kudelski recap checks, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice requiring a victim-matrix change; Insurity's July 9 status update, Autodesk's no-impact advisory, and retained direct notices continue to control each organization's boundary, while duplicate/SEO recaps, generic OAuth commentary, leak-site-only claims, social posts, and aggregator-only victim tracking were not promoted. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 02-Aug-2026 1:30 AM ET. PANDA index date already shows Updated Aug 1, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
02-Aug-2026 · Monitor run Run: 02-Aug-2026 9:32 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed direct customer-disclosure delta incorporated. Newly retained (publication date not visible): Yext Trust Center Klue Security Incident, retrieved 02-Aug-2026 9:32 PM ET. No Freshly reported (<24h) or Newly retained (>24h) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Klue Salesforce/Gong restoration and CTO lessons-learned posts, Yext/Commvault/NetDocuments/Cresta/Insurity/Autodesk/BeyondTrust/OneTrust/Confluent/Snyk/Pendo/Camunda/Saviynt/Jamf leads, CSO/SOCRadar/BankInfoSecurity/Softonic/Nudge Security/Field Effect/ThreatLocker/Kudelski/Rescana/Mallory recap checks, and Salesloft Drift comparator updates. Public-victim/disclosure search found Yext's direct SafeBase trust-center notice and rejected duplicate or secondary recaps, generic OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking, and Commvault/NetDocuments JavaScript-only or empty direct retrievals without stable inspectable public bodies. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 03-Aug-2026 1:30 AM ET. PANDA index date already shows Updated Aug 2, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
03-Aug-2026 · Monitor run Run: 03-Aug-2026 9:32 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed direct customer-disclosure deltas incorporated. Newly retained (>24h): Commvault Trust Center Klue Security Update: What Happened and What Customers Should Know, published 13-Jul-2026 and retrieved 03-Aug-2026 9:32 PM ET; NetDocuments TrustShare The NetDocuments Service Not Impacted by Klue Security Incident, published 26-Jun-2026 3:20 PM ET and retrieved 03-Aug-2026 9:32 PM ET. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Klue Salesforce/Gong restoration and CTO lessons-learned posts, Commvault/NetDocuments/Yext/Cresta/Insurity/Autodesk/BeyondTrust/OneTrust/Confluent/Snyk/Pendo/Camunda/Saviynt/Jamf leads, Commvault and NetDocuments rendered trust-center checks, duplicate/SEO recaps, generic OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking, and Salesloft Drift comparator updates. Public-victim/disclosure search found Commvault and NetDocuments rendered public notices and rejected duplicate or unsupported material. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 04-Aug-2026 1:30 AM ET. PANDA index date updated to Updated Aug 3, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
04-Aug-2026 · Monitor run Run: 04-Aug-2026 9:31 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed direct customer-disclosure delta incorporated. Newly retained (>24h): Neon One Notice of Data Breach, dated 31-Jul-2026 and retrieved 04-Aug-2026 9:31 PM ET. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Klue Salesforce/Gong restoration and CTO lessons-learned posts, Neon One/ClaimDepot breach-notice leads, Commvault/NetDocuments/Yext/Cresta/Insurity/Autodesk/BeyondTrust/OneTrust/Confluent/Snyk/Pendo/Camunda/Saviynt/Jamf leads, generic legal SEO recaps, duplicate media, leak-site-only claims, social posts, aggregator-only victim tracking, and Salesloft Drift comparator updates. Public-victim/disclosure search found Neon One's direct notice letter and rejected the ClaimDepot Klue recap as duplicative/partly inconsistent with primary Klue timing, generic OAuth commentary, and unsupported actor conflation. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 05-Aug-2026 1:30 AM ET. PANDA index date updated to Updated Aug 4, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
06-Aug-2026 · Monitor run Run: 06-Aug-2026 9:31 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Klue Salesforce/Gong restoration and CTO lessons-learned posts, Snyk/Cresta/Insurity/Recorded Future/eSentire/Autodesk/Commvault/NetDocuments/Yext/Neon One/BeyondTrust/OneTrust/Confluent/Pendo/Camunda/Saviynt/Jamf leads, Delinea/CybelAngel/Cybersecurity Dive/Datadog/Nudge Security/Rescana/BankInfoSecurity/CyberPress/ITBranschen recap checks, generic OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice requiring a victim-matrix change; Snyk, Cresta, Insurity, Recorded Future, eSentire, Neon One, Yext, Commvault, NetDocuments, Autodesk, and retained direct notices continue to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 07-Aug-2026 1:30 AM ET. PANDA index date updated to Updated Aug 6, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
07-Aug-2026 · Monitor run Run: 07-Aug-2026 9:35 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Klue Salesforce/Gong restoration and CTO lessons-learned posts, Snyk/Cresta/Insurity/Recorded Future/eSentire/Autodesk/Commvault/NetDocuments/Yext/Neon One/BeyondTrust/OneTrust/Confluent/Pendo/Camunda/Saviynt/Jamf leads, Delinea/CybelAngel/RH-ISAC/Cybersecurity Dive/Datadog/Nudge Security/Rescana/BankInfoSecurity/CyberPress/ITBranschen/TechCrunch/ThreatLocker/Kudelski/Beazley/Shadowtier recap checks, generic OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice requiring a victim-matrix change; Snyk's rendered trust-center Klue closure remains the already retained July 8 update, the August 5 Snyk trust-center result concerned a separate npm supply-chain incident, and retained direct notices continue to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 08-Aug-2026 1:30 AM ET. PANDA index date updated to Updated Aug 7, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
08-Aug-2026 · Monitor run Run: 08-Aug-2026 9:31 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Klue Salesforce/Gong restoration and CTO lessons-learned posts, Snyk/Cresta/Insurity/Recorded Future/eSentire/Autodesk/Commvault/NetDocuments/Yext/Neon One/BeyondTrust/OneTrust/Confluent/Pendo/Camunda/Saviynt/Jamf leads, Salesforce Trust status, legal/SEO recap pages, Vectra/Hard2bit/Beazley/Kudelski/ThreatLocker/Field Effect/Rescana/CSO/The Hacker News recap checks, generic OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice requiring a victim-matrix change; Insurity's current status result remains the already retained July 9 update, Snyk's rendered trust-center Klue closure remains the already retained July 8 update, Neon One remains represented by the retained July 31 notice letter, and retained direct notices continue to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 09-Aug-2026 1:30 AM ET. PANDA index date already shows Updated Aug 8, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
09-Aug-2026 · Monitor run Run: 09-Aug-2026 9:32 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Klue Salesforce/Gong restoration and CTO lessons-learned posts, Insurity/Thinkproject/Cresta/Snyk/Pendo/Recorded Future/eSentire/Autodesk/Commvault/NetDocuments/Yext/Neon One/BeyondTrust/OneTrust/Confluent/Camunda/Saviynt/Jamf leads, Salesforce Trust status, Delinea/Obsidian/ThreatLocker/Field Effect/Zscaler/Kudelski/Rescana/RH-ISAC/CSA/Microsoft/The Hacker News recap and campaign-deconfliction checks, generic OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice requiring a victim-matrix change; Insurity's current status content remains the already retained July 9 update, Thinkproject's August 5 status text did not change its retained UAT CRM/product-boundary analysis, Cresta/Pendo/Snyk and other retained direct notices continue to control each organization's boundary, and duplicate/SEO/generic/comparator coverage was not promoted. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 10-Aug-2026 1:30 AM ET. PANDA index date updated to Updated Aug 9, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
10-Aug-2026 · Monitor run Run: 10-Aug-2026 9:36 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed direct customer-disclosure delta incorporated. Newly retained (>24h): Massachusetts Attorney General Data Breach Notification Portal / Betterment 2026-1291 - Betterment PDF, published 05-Aug-2026 and retrieved 10-Aug-2026 9:36 PM ET. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Klue Salesforce/Gong restoration and CTO lessons-learned posts, Betterment/Neon One/ClassActionU/ClaimDepot/Mass.gov breach-notice leads, Snyk/Cresta/Insurity/Recorded Future/eSentire/Autodesk/Commvault/NetDocuments/Yext/BeyondTrust/OneTrust/Confluent/Pendo/Camunda/Saviynt/Jamf leads, Salesforce Trust status, Delinea/Obsidian/ThreatLocker/Field Effect/Zscaler/Kudelski/Rescana/RH-ISAC/CSA/Microsoft/The Hacker News recap and campaign-deconfliction checks, generic OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking, and Salesloft Drift comparator updates. Public-victim/disclosure search found Betterment's Mass.gov-hosted public notice-letter PDF and rejected duplicate legal SEO recaps, the unrelated January Betterment/ShinyHunters reporting, leak-site-only claims, social posts, generic OAuth commentary, and unsupported Klue/Salesloft Drift/ShinyHunters/Storm-3138 conflation. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 11-Aug-2026 1:30 AM ET. PANDA index date already shows Updated Aug 10, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
11-Aug-2026 · Monitor run Run: 11-Aug-2026 9:30 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed public notice scoping delta incorporated from an already-retained primary PDF. Newly retained (>24h): Massachusetts Attorney General Data Breach Notification Portal / Betterment 2026-1291 - Betterment PDF, published 05-Aug-2026, originally retrieved 10-Aug-2026 9:36 PM ET, and PDF text re-reviewed 11-Aug-2026 9:30 PM ET. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Klue Salesforce/Gong restoration and CTO lessons-learned posts, Betterment/Mass.gov/Dapeer legal recap leads, Snyk/Cresta/Insurity/Recorded Future/eSentire/Autodesk/Commvault/NetDocuments/Yext/Neon One/BeyondTrust/OneTrust/Confluent/Pendo/Camunda/Saviynt/Jamf leads, Salesforce Trust status, Delinea/ThreatLocker/Beazley/CSA/Microsoft/The Hacker News recap and campaign-deconfliction checks, generic OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new named organization beyond retained sources, but re-reviewed the Mass.gov Betterment PDF and promoted the notice's public data-category/system-boundary text: name and Social Security number in the accessed file, no unauthorized access to Betterment computer systems, and two years of Kroll identity monitoring. Duplicate legal SEO recaps, generic commentary, and unsupported Klue/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 12-Aug-2026 1:30 AM ET. PANDA index date updated to Updated Aug 11, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
12-Aug-2026 · Monitor run Run: 12-Aug-2026 9:30 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Klue Salesforce/Gong restoration and CTO lessons-learned posts, Betterment/Mass.gov/Dapeer legal recap leads, Snyk/Cresta/Insurity/Recorded Future/eSentire/Autodesk/Commvault/NetDocuments/Yext/Neon One/BeyondTrust/OneTrust/Confluent/Pendo/Camunda/Saviynt/Jamf leads, Salesforce Trust status, BleepingComputer City-Forum Salesforce/ServiceNow portal reporting, CSA/Microsoft/The Hacker News recap and campaign-deconfliction checks, generic OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF and Dapeer remains duplicate legal/SEO commentary derived from that notice. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 13-Aug-2026 1:30 AM ET. PANDA index date updated to Updated Aug 12, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
13-Aug-2026 · Monitor run Run: 13-Aug-2026 9:31 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Klue Salesforce/Gong restoration and CTO lessons-learned posts, Betterment/Mass.gov/Dapeer/ClassActionU legal recap leads, Neon One/ClaimDepot/ClassActionU legal recap leads, Snyk/Cresta/Insurity/Recorded Future/eSentire/Autodesk/Commvault/NetDocuments/Yext/BeyondTrust/OneTrust/Confluent/Pendo/Camunda/Saviynt/Jamf leads, Salesforce Trust status, Delinea/Obsidian/ThreatLocker/Field Effect/Rescana/RH-ISAC/CSA/Microsoft/The Hacker News recap and campaign-deconfliction checks, generic OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Neon One remains represented by the retained July 31 notice letter, and Dapeer, ClaimDepot, ClassActionU, and similar legal/SEO recaps were treated as duplicate secondary commentary rather than new source-backed deltas. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 14-Aug-2026 1:30 AM ET. PANDA index date updated to Updated Aug 13, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
14-Aug-2026 · Monitor run Run: 14-Aug-2026 9:31 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Klue Salesforce/Gong restoration and CTO lessons-learned posts, Betterment/Mass.gov/Dapeer/ClaimDepot legal recap leads, Commvault/Jamf/Snyk/Cresta/Insurity/Recorded Future/eSentire/Autodesk/NetDocuments/Yext/Neon One/BeyondTrust/OneTrust/Confluent/Pendo/Camunda/Saviynt/Sprout Social leads, Salesforce Trust status, Delinea/Obsidian/SpyCloud/ThreatLocker/BankInfoSecurity/Rescana/CSA/Microsoft/The Hacker News/TechCrunch/LinkedIn/social recap and campaign-deconfliction checks, generic OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Commvault remains represented by the retained trust-center boundary and the July 24 Commvault blog was treated as duplicate context, Snyk's current trust-center result concerned a separate npm supply-chain incident, and retained direct notices continue to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 15-Aug-2026 1:30 AM ET. PANDA index date updated to Updated Aug 14, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
15-Aug-2026 · Monitor run Run: 15-Aug-2026 9:32 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Snyk/Cresta/Lucanet/Pendo/Sprout Social trust-center recrawls, Betterment/Mass.gov/Dapeer/ClassActionU legal recap leads, Delinea/CSA/Mitiga/Dark Reading/BlackFog/Rescana/RH-ISAC/Kudelski/SOCRadar/Beazley/TechCrunch/The Hacker News/SecurityWeek/LinkedIn/social recap and campaign-deconfliction checks, generic OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Snyk's current trust-center result remains the already retained Klue closure or separate npm incident context, and retained direct notices continue to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 16-Aug-2026 1:30 AM ET. PANDA index date updated to Updated Aug 15, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
16-Aug-2026 · Monitor run Run: 16-Aug-2026 9:31 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed public status-resolution delta incorporated. Newly retained (>24h): Thinkproject Status Klue Breach that Allowed Data Exfiltration from Salesforce, updated/resolved 12-Aug-2026 2:01 PM and retrieved 16-Aug-2026 9:31 PM ET. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Thinkproject/Snyk/Cresta/Recorded Future/eSentire/Autodesk/Commvault/NetDocuments/Yext/Neon One/Betterment/BeyondTrust/OneTrust/Confluent/Pendo/Camunda/Saviynt/Jamf leads, Salesforce Trust status, Delinea/Nudge Security/SOCRadar/Field Effect/Kudelski/Rescana/RH-ISAC/CSA/Microsoft/The Hacker News/TechCrunch/SecurityWeek/LinkedIn/social recap and campaign-deconfliction checks, generic OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking, and Salesloft Drift comparator updates. Public-victim/disclosure search found Thinkproject's direct Aug. 12 status resolution and rejected duplicate secondary recaps, generic Salesforce/OAuth commentary, legal/SEO rewrites, leak-site-only claims, social posts, and aggregator-only victim tracking without direct organization-specific public notice bodies. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 17-Aug-2026 1:30 AM ET. PANDA index date already shows Updated Aug 16, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
17-Aug-2026 · Monitor run Run: 17-Aug-2026 9:32 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Thinkproject/Snyk/Cresta/Recorded Future/eSentire/Autodesk/Commvault/NetDocuments/Yext/Neon One/Betterment/BeyondTrust/OneTrust/Confluent/Pendo/Camunda/Saviynt/Jamf leads, regulator-hosted notice searches, Delinea/Nudge Security/SOCRadar/Field Effect/Kudelski/Rescana/RH-ISAC/CSA/Microsoft/The Hacker News/TechCrunch/SecurityWeek/LinkedIn/social recap and campaign-deconfliction checks, generic OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Thinkproject remains represented by the retained Aug. 12 status resolution, Snyk's rendered trust-center Klue closure remains retained, and retained direct notices continued to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Delinea's August 2026 Drift-to-Klue recap was treated as duplicate comparator commentary and not promoted because it did not add Klue-specific primary evidence and included victim-list language not supported by the retained source set. | Next scheduled monitor: 18-Aug-2026 1:30 AM ET. PANDA index date updated to Updated Aug 17, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
18-Aug-2026 · Monitor run Run: 18-Aug-2026 9:31 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Klue primary incident and CrowdStrike-summary posts, Thinkproject/Betterment/Neon One/Commvault/NetDocuments/Snyk/Cresta/Insurity/Recorded Future/eSentire/Autodesk/Yext/BeyondTrust/OneTrust/Confluent/Pendo/Camunda/Saviynt/Jamf leads, regulator-hosted notice searches, Delinea/Nudge Security/SOCRadar/ThreatLocker/Rescana/RH-ISAC/CSA/Microsoft/The Hacker News/TechCrunch/SecurityWeek/LinkedIn/social recap and campaign-deconfliction checks, generic OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Thinkproject remains represented by the retained Aug. 12 status resolution, and retained direct notices continued to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Delinea's August 2026 Drift-to-Klue recap and similar Salesforce/OAuth explainers remained duplicate comparator commentary and were not promoted. | Next scheduled monitor: 19-Aug-2026 1:30 AM ET. PANDA index date updated to Updated Aug 18, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
19-Aug-2026 · Monitor run Run: 19-Aug-2026 9:31 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Klue primary incident and restoration posts, Thinkproject/Betterment/Neon One/Commvault/NetDocuments/Snyk/Cresta/Insurity/Recorded Future/eSentire/Autodesk/Yext/BeyondTrust/OneTrust/Confluent/Pendo/Camunda/Saviynt/Jamf/Sprout Social/LastPass leads, regulator-hosted notice searches, ClaimDepot/ClassActionU/Federman legal recaps, Coverbase/Akeyless/ThreatLocker/Field Effect/Kudelski/Rescana/Delinea/SpyCloud/BankInfoSecurity/Dark Reading/TechRadar/Softonic/LinkedIn/social recap and campaign-deconfliction checks, generic OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Thinkproject remains represented by the retained Aug. 12 status resolution, Neon One remains represented by the retained Nebraska AG notice letter, and retained direct notices continued to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Legal/SEO pages and NHI/OAuth explainers were treated as duplicates or generic commentary because they did not add primary Klue evidence, organization-specific notice boundaries, Salesforce forensic detail, or reliable attribution changes. | Next scheduled monitor: 20-Aug-2026 1:30 AM ET. PANDA index date already shows Updated Aug 19, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
20-Aug-2026 · Monitor run Run: 20-Aug-2026 9:31 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Klue primary incident/restoration/CTO posts and the Aug. 20 Claude connector product post, Thinkproject/Betterment/Neon One/Commvault/NetDocuments/Snyk/Cresta/Insurity/Recorded Future/eSentire/Autodesk/Yext/BeyondTrust/OneTrust/Confluent/Pendo/Camunda/Saviynt/Jamf/Sprout Social/LastPass leads, regulator-hosted notice searches, BankInfoSecurity/TechRadar/Softonic/SecurityWeek/Field Effect/Beazley/Delinea/Coverbase/Akeyless/ThreatLocker/Kudelski/Rescana/RH-ISAC/CSA/Microsoft/The Hacker News/LinkedIn/social recap and campaign-deconfliction checks, generic OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking, kluebreach.com/driftbreach.com tracking, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Thinkproject remains represented by the retained Aug. 12 status resolution, Neon One remains represented by the retained Nebraska AG notice letter, and retained direct notices continued to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. BankInfoSecurity, Delinea, Nudge Security, Field Effect, Beazley, SalesforceBen, Rescana/FiduciaryTech, and CSA-style comparator results were treated as duplicate, generic, or insufficiently reliable for changing Klue-specific attribution or victimology. | Next scheduled monitor: 21-Aug-2026 1:30 AM ET. PANDA index date already shows Updated Aug 20, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
21-Aug-2026 · Monitor run Run: 21-Aug-2026 9:32 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Klue primary incident/restoration/CTO posts, Huntress support, Snyk/Cresta/Insurity/Recorded Future/eSentire/Autodesk/Commvault/NetDocuments/Yext/Neon One/Betterment/Thinkproject/BeyondTrust/OneTrust/Confluent/Pendo/Camunda/Saviynt/Jamf/Sprout Social/LastPass leads, regulator-hosted notice searches, BankInfoSecurity/Dark Reading/TechRadar/Softonic/SecurityWeek/Cybersecurity Dive/Delinea/Coverbase/Nudge Security/ThreatLocker/Beazley/CSA/Microsoft/RH-ISAC/Rescana/SOCRadar/Mallory.ai/LinkedIn/social recap and campaign-deconfliction checks, generic OAuth commentary, legal/SEO recap pages, leak-site-only claims, social posts, aggregator-only victim tracking, kluebreach.com tracking, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Thinkproject remains represented by the retained Aug. 12 status resolution, Neon One remains represented by the retained Nebraska AG notice letter, and retained direct notices continued to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Mallory.ai, Rescana, ClassActionU/Dapeer-style legal pages, LinkedIn/social reposts, and Salesforce/OAuth explainers were treated as duplicate, aggregate, generic, or insufficiently reliable for changing Klue-specific attribution, victimology, Salesforce forensics, or stakeholder messaging. | Next scheduled monitor: 22-Aug-2026 1:30 AM ET. PANDA index date updated to Updated Aug 21, 2026. Email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, and all external notifications intentionally not used per the automation's non-negotiable no-email policy. |
22-Aug-2026 · Monitor run Run: 22-Aug-2026 9:32 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Klue primary incident/restoration/CTO posts, Camunda/BeyondTrust/OneTrust/Snyk/Sprout Social/LastPass/Betterment/Neon One/Thinkproject direct-notice leads, regulator-hosted notice searches, BleepingComputer Salesforce index, Bright Defense aggregate breach list, Delinea/CSA/Mitiga/SalesforceBen/ThreatLocker/Rescana/Nudge Security/Beazley/Coverbase/TechRadar/Wired/Dark Reading/BankInfoSecurity/LinkedIn/social recap and campaign-deconfliction checks, legal/SEO recap pages, leak-site-only claims, aggregator-only victim tracking, kluebreach.com tracking, and Salesloft Drift/Gainsight comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Thinkproject remains represented by the retained Aug. 12 status resolution, Neon One remains represented by the retained Nebraska AG notice letter, and retained direct notices continued to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Dapeer/ClassActionU-style legal pages, Bright Defense and kluebreach.com aggregate tracking, LinkedIn/Facebook/Instagram reposts, Rescana/SalesforceBen/Delinea/CSA comparator summaries, and Salesforce/OAuth explainers were treated as duplicate, aggregate, generic, or insufficiently reliable for changing Klue-specific attribution, victimology, Salesforce forensics, or stakeholder messaging. | Next scheduled monitor: 23-Aug-2026 1:30 AM ET. PANDA index date already shows Updated Aug 22, 2026. Email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, and all external notifications intentionally not used per the automation's non-negotiable no-email policy. |
23-Aug-2026 · Monitor run Run: 23-Aug-2026 9:33 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Klue primary incident/restoration/CTO posts, Obsidian updated analysis, kluebreach.com/Nudge aggregate tracking, Beazley advisory, ThreatLocker, Field Effect, Rescana, Dark Reading, TechRadar, SecurityWeek, BankInfoSecurity, RH-ISAC, LinkedIn/social recaps, regulator-hosted notice searches, and Salesloft Drift/Gainsight comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Thinkproject remains represented by the retained Aug. 12 status resolution, Neon One remains represented by the retained Nebraska AG notice letter, and retained direct notices continued to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Search snippets and aggregate trackers were treated as insufficient for new organization-specific impact-boundary rows without direct public notice bodies. | Next scheduled monitor: 24-Aug-2026 1:30 AM ET. PANDA index date updated to Updated Aug 23, 2026. Email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, and all external notifications intentionally not used per the automation's non-negotiable no-email policy. |
24-Aug-2026 · Monitor run Run: 24-Aug-2026 9:32 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Klue primary incident/restoration/CTO posts, Snyk/Cresta/Insurity/Recorded Future/eSentire/Autodesk/Commvault/NetDocuments/Yext/Neon One/Betterment/Thinkproject/BeyondTrust/OneTrust/Confluent/Pendo/Camunda/Saviynt/Jamf/Sprout Social/LastPass leads, regulator-hosted notice searches, BleepingComputer Salesforce index, Cybersecurity Dive, Delinea Drift-to-Klue recap, Akeyless, Coverbase, ThreatLocker, Kudelski, Obsidian, RedLegg, Rescana, SOCRadar, SecurityWeek, BankInfoSecurity, Infosecurity Magazine, TechRadar, Softonic, LinkedIn/Facebook/Instagram/social recaps, generic OAuth and non-human-identity commentary, legal/SEO recap pages, leak-site-only claims, aggregate breach trackers including Bright Defense and kluebreach.com/Nudge, and Salesloft Drift/Gainsight comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Thinkproject remains represented by the retained Aug. 12 status resolution, Neon One remains represented by the retained Nebraska AG notice letter, and retained direct notices continued to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Fresh crawler hits, search snippets, aggregate trackers, and Salesforce/OAuth explainers were treated as duplicate, aggregate, generic, or insufficiently reliable for changing Klue-specific attribution, victimology, Salesforce forensics, stakeholder messaging, or source deconfliction. | Next scheduled monitor: 25-Aug-2026 1:30 AM ET. PANDA index date updated to Updated Aug 24, 2026. Email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, and all external notifications intentionally not used per the automation's non-negotiable no-email policy. |
25-Aug-2026 · Monitor run Run: 25-Aug-2026 9:32 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, Klue OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress Klue investigation, Datadog Klue detection guidance, ReliaQuest Klue analysis, BleepingComputer Klue, Cybersecurity Dive Klue, Help Net Security Klue, The Hacker News Klue, Jamf Klue notice, Sprout Social Klue notice, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, Klue primary incident/restoration/CTO posts, Klue Aug. 20 Claude connector product post, Klue Aug. 24 competitive-deal-support product post, Snyk/Cresta/Insurity/Recorded Future/eSentire/Autodesk/Commvault/NetDocuments/Yext/Neon One/Betterment/Thinkproject/BeyondTrust/OneTrust/Confluent/Pendo/Camunda/Saviynt/Jamf/Sprout Social/LastPass leads, regulator-hosted notice searches, Dapeer legal recap, The Hacker News Microsoft/ShinyHunters recap, SpyCloud, BlackFog, Bright Defense, kluebreach.com/Nudge aggregate tracking, Protos Labs, Zscaler, Dark Reading, SalesforceBen, SecurityWeek, RH-ISAC, Rescana, ThreatLocker, Delinea, LinkedIn/social recaps, generic OAuth and non-human-identity commentary, leak-site-only claims, and Salesloft Drift/Gainsight comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Thinkproject remains represented by the retained Aug. 12 status resolution, Neon One remains represented by the retained Nebraska AG notice letter, and retained direct notices continued to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Klue's Aug. 20 and Aug. 24 product posts were not promoted because they did not update the security incident. Fresh crawler hits, search snippets, aggregate trackers, legal recaps, and Salesforce/OAuth explainers were treated as duplicate, aggregate, generic, or insufficiently reliable for changing Klue-specific attribution, victimology, Salesforce forensics, stakeholder messaging, or source deconfliction. | Next scheduled monitor: 26-Aug-2026 1:30 AM ET. PANDA index date updated to Updated Aug 25, 2026. Email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, and all external notifications intentionally not used per the automation's non-negotiable no-email policy. |
6-Why It Matters
This event matters because CRM integrations often become invisible trust bridges. A sales-enablement vendor may not look like a crown-jewel system, but its OAuth access can provide a route into customer contacts, accounts, opportunity data, competitive notes, and relationship metadata. That makes the incident relevant to breach response, privacy review, business-development exposure, sales operations, and vendor-risk governance.
Supply-chain blast radius
A single trusted SaaS integration can expose many downstream Salesforce tenants.
Token-first response
Password resets do not address OAuth refresh tokens, connected-app grants, or API access.
CRM impact
Exposed data may include customer/prospect contact details, account notes, and commercial context.
7-Timeline
| Date / Period | Event | Source-Backed Meaning | Source |
|---|---|---|---|
| June 11, 2026 | Datadog reports early anomalous Klue/Salesforce activity in monitored telemetry. | Suggested starting point for Salesforce log scoping where Klue was connected. | 6 |
| June 12, 2026 | Klue says it identified unauthorized activity affecting a portion of its integration infrastructure. | Primary vendor acknowledgement of the incident window. | 1 |
| June 13, 2026 | LastPass says Klue notified it of a security incident involving Salesforce data. | Confirmed downstream customer-notification path. | 3 |
| June 18, 2026 | Huntress publishes a victim/researcher account about Salesforce data impacted through Klue. | Public technical/customer signal that the blast radius is broader than one company. | 7 |
| June 20, 2026 | Security media report Klue investigating a supply-chain attack involving Salesforce integrations. | Public awareness broadens beyond direct customer notices. | 8 |
| June 22, 2026 | Klue publishes an update, LastPass publishes a detailed response page, and ReliaQuest publishes technical analysis of the Klue integration abuse. | Source set becomes strong enough for mechanism-level briefing and downstream-customer scoping. | 1,5,30 |
| June 23, 2026 | BleepingComputer reports LastPass confirmation and connects the incident to the Klue supply-chain attack. | Starter public article for this PANDA brief. | 4 |
| June 24, 2026 | SecurityWeek reports that over a dozen Klue customers had confirmed Salesforce-instance data theft and names BeyondTrust and LastPass among impacted organizations. | Expanded public victim/disclosure boundary beyond the initial LastPass/Huntress/Jamf/Sprout Social examples. | 32 |
| June 25, 2026 | Obsidian publishes analysis across impacted organizations, adding Global Describe reconnaissance, v59.0 API usage, QueryMore pagination, user-agent deviation, and object-harvest detail. | Improves Salesforce forensic scoping beyond generic REST API volume. | 37 |
| June 25, 2026 | TechCrunch reports Klue told customers that the original criminals were deleting stolen customer data while a second group had begun making threats. | Shifts scoping from one extortion channel to possible follow-on customer pressure and proof-validation questions. | 31 |
| June 26, 2026 | SecurityWeek reports roughly two dozen public Klue-Salesforce impact disclosures and names additional organizations with customer notices. | Expands the public victim/disclosure set while preserving customer-specific impact boundaries. | 36 |
| June 26, 2026 | 27-Jun-2026 · Newly retained (>24h) LogicMonitor publishes a direct Klue notice for the Catchpoint Salesforce environment. | Adds a primary customer disclosure that separates affected Salesforce data from LogicMonitor production, monitoring, and primary Salesforce systems. | 41 |
| June 28, 2026 monitor retrieval | 28-Jun-2026 · Newly retained (>24h) OneTrust, Gong, and Insurity direct notices are retained as first-party disclosure boundaries. | Adds customer/platform-specific limits for Salesforce CRM exposure, Gong integration exposure, credential rotation, and product/customer-tenant boundaries. | 44,45,46 |
| June 29, 2026 monitor retrieval | 29-Jun-2026 · Freshly reported (<24h) AudienceView status page is retained for its fresh resolution timestamp and organization-specific Klue-Salesforce boundary. 29-Jun-2026 · Newly retained (>24h) Link11, FINRA, and ZeroFox are retained as older source-backed additions. 29-Jun-2026 · Newly retained (publication date not visible) AlertMedia, Camunda, Cresta, and Lucanet trust-center notices are retained as undated direct disclosures. | Adds primary customer-disclosure boundaries, sector guidance, Icarus/ICARUS deconfliction, and limited IOC coverage without changing the Salesforce-platform-vulnerability boundary. | 47,48,49,50,51,52,53,54 |
| June 30, 2026 monitor retrieval | 30-Jun-2026 · Newly retained (>24h) ControlUp, Deel, and Saviynt direct disclosures are retained as older source-backed public victim notices. 30-Jun-2026 · Newly retained (publication date not visible) ABBYY is retained as an undated trust-center disclosure. | Expands direct public customer-disclosure coverage while preserving organization-specific Salesforce, CRM, product, infrastructure, and customer-data boundaries. | 55,56,57,58 |
| June 30, 2026 | 02-Jul-2026 · Freshly reported (<24h) CrowdStrike completes its Klue investigation, according to Klue's July 1/2 public summary. | Adds primary-source confidence around investigation scope, containment, and post-incident monitoring. | 59 |
| July 1, 2026 | 02-Jul-2026 · Newly retained (>24h) Camunda updates its trust-center notice to state exfiltrated data did not include support data and was limited to standard business-contact and account information in Salesforce CRM. | Narrows one previously retained customer disclosure boundary rather than adding a new victim category. | 50 |
| July 1-2, 2026 | 02-Jul-2026 · Freshly reported (<24h) Klue publishes CrowdStrike findings: a compromised GitHub PAT introduced unauthorized code into the integration service and collected third-party credentials including Salesforce OAuth tokens. | Materially refines the root-cause and control-plane story from OAuth abuse alone to source-control, CI/CD, integration-service, and token-collection controls. | 59 |
| July 4, 2026 monitor retrieval | 04-Jul-2026 · Newly retained (publication date not visible) Postman's Security & Trust Portal notice is retained as a direct public customer disclosure. | Adds a named Salesforce/Gong boundary: customer contact and sales information was exfiltrated from Salesforce through Klue, while customer data was not accessed from Gong and core platform services remained secure. | 60 |
| July 5, 2026 monitor retrieval | 05-Jul-2026 · Newly retained (>24h) Automox's June 29 trust-center notice is retained as a direct no-impact disclosure and leak-list deconfliction source. | Adds a named organization that reviewed Klue/Salesforce exposure, found no anomalous Salesforce activity, and says Klue had no indication Automox or customer data was affected. | 61 |
| July 7, 2026 monitor retrieval | 07-Jul-2026 · Newly retained (>24h) eSentire's June 26 blog is retained as a direct customer disclosure. | Adds a named Salesforce-impact boundary with minimal exposure, restricted OAuth-permission context, and explicit exclusions for customer communication/support interactions, threat intelligence, telemetry, credentials, passwords, and payment-card data. | 62 |
| July 8, 2026 monitor retrieval | 08-Jul-2026 · Newly retained (>24h) Thinkproject's June 26 status notice is retained as a direct customer disclosure. | Adds a UAT CRM-specific boundary: possible business-contact and commercial-information exposure through Salesforce/Klue, with products, services, and customer product platform excluded. | 63 |
| August 12, 2026 | 16-Aug-2026 · Newly retained (>24h) Thinkproject resolves its public Klue status incident. | Adds a closure boundary to the already-retained Thinkproject row: investigation concluded, no known misuse of affected data, and continued monitoring without expanding product, service, or customer product-platform impact. | 63 |
| July 8, 2026 | 09-Jul-2026 · Newly retained (>24h) Snyk resolves its Klue/Salesforce status incident after a Mandiant-assisted forensic investigation. | Closes the Snyk boundary as business CRM data only, with no evidence of Snyk platform or sensitive platform-data impact. | 64 |
| July 9, 2026 | 09-Jul-2026 · Freshly reported (<24h) Secure ISS publishes a SentinelOne Klue advisory based on a partner notification. | Adds a qualified SentinelOne public advisory boundary: impact contained to Salesforce through the Klue API integration, no lateral movement or core-product/cloud/production impact reported, with data analysis still ongoing. | 65 |
| July 10, 2026 | 11-Jul-2026 · Newly retained (>24h) OneTrust updates its Klue incident post to state that the technical investigation, scope validation, containment, and remediation are complete. | Narrows OneTrust's boundary to no evidence of exposure beyond its Salesforce environment while preserving ongoing governance, compliance, and notification review. | 44 |
| July 13, 2026 | 13-Jul-2026 · Freshly reported (<24h) Microsoft publishes Salesforce/SaaS OAuth-abuse research that includes Klue integration activity in a broader ShinyHunters-associated tradecraft discussion. 18-Jul-2026 · Newly retained (>24h) The AI Monitoring Agent now retains Microsoft's Storm-3138 activity label for the Klue system-access path. | Adds high-confidence deconfliction: Microsoft reinforces trusted OAuth abuse and supplies Klue IOC context, but does not by itself collapse the Klue-specific Icarus/ICARUS extortion label into UNC6395, Salesloft Drift, or a definitive ShinyHunters attribution. | 66 |
| July 14, 2026 monitor retrieval | 14-Jul-2026 · Newly retained (publication date not visible) Sisense Trust Center notice is retained as an undated direct customer disclosure. | Adds a named public customer boundary: certain business and sales-related Salesforce CRM data, with Sisense product-platform and product-platform data excluded. | 67 |
| July 16, 2026 monitor retrieval | 16-Jul-2026 · Newly retained (>24h) Qualtrics and Splashtop direct customer notices are retained as older source-backed public disclosures. | Adds two organization-specific Salesforce/Klue boundaries: Qualtrics limits impact to a subset of Salesforce B2B identifiers and excludes Qualtrics platform customer data; Splashtop limits current belief to business data fields in Salesforce, excludes product/service impact, and keeps investigation ongoing. | 68,69 |
| July 23, 2026 monitor retrieval | 23-Jul-2026 · Newly retained (>24h) Greenhouse's June 24 and Blackbaud's July 22 Conveyor trust-center notices are retained as direct public customer disclosures. | Adds two organization-specific boundaries: Greenhouse confirms limited business-contact data in sales/customer relationship systems and excludes product, hiring, candidate, infrastructure, modification, and deletion impact; Blackbaud says its investigation remains ongoing with no substantive update and no known product or business-operations impact. | 70,71 |
| July 28, 2026 monitor retrieval | 28-Jul-2026 · Newly retained (>24h) Autodesk's June 23 trust-center advisory is retained as an older direct no-impact public disclosure. | Adds one named organization-specific boundary: Autodesk investigated after Klue notification, says it did not use the Salesforce or Gong integrations for Klue, and reports no direct Autodesk product, service, or system impact. | 73 |
| July 30, 2026 monitor retrieval | 30-Jul-2026 · Newly retained (>24h) Klue's July 27 restoration post is retained as an older primary vendor update. | Changes operational posture from temporary integration disablement only to controlled re-enablement: Klue says Salesforce and Gong marketplace integrations were reinstated and lists post-incident controls customers should validate before reauthorization. | 74 |
| July 31, 2026 | 31-Jul-2026 · Freshly reported (<24h) Klue publishes a CTO lessons-learned post on the security incident and modern SaaS platform controls. | Adds fresh primary detail for engineering and vendor-risk review: two-phase GitHub PAT and credential discovery, unauthorized build/deployment path, tampered production workload, stored OAuth-token access, June 12 containment, and durable CI/CD, credential, OAuth, and distributed-evidence lessons. | 75 |
| August 2, 2026 monitor retrieval | 02-Aug-2026 · Newly retained; undated Yext's SafeBase trust-center notice is retained as an undated direct customer disclosure. | Adds one organization-specific boundary: read-only Salesforce CRM queries for about 17 hours on June 11-12, business contact details for customers and prospects exposed, and Yext platform/product/infrastructure/customer-content/customer-facing-system/end-user-data/payment-card/Google Workspace/Slack exclusions. | 76 |
| August 3, 2026 monitor retrieval | 03-Aug-2026 · Newly retained (>24h) Commvault's July 13 rendered Vanta notice and NetDocuments' June 26 rendered TrustShare advisory are retained as older direct public disclosures. | Adds two organization-specific boundaries: Commvault confirms Salesforce business relationship/sales activity data access while excluding customer data and product/service/backup/log impact; NetDocuments confines impact to an internal Gong-user staff list and excludes customer, prospect, Customer Repository Data, and service impact. | 77,78 |
| August 4, 2026 monitor retrieval | 04-Aug-2026 · Newly retained (>24h) Neon One's July 31 Notice of Data Breach is retained as an older direct public notice letter. | Adds one organization-specific boundary: a Klue incident involving Neon One's Salesforce CRM integration service caused unauthorized access to some personal information between June 11-12, the incident was contained, and no further impact was identified. | 79 |
| August 10-11, 2026 monitor retrieval and re-review | 10-Aug-2026 · Newly retained (>24h) Betterment's August 5 Mass.gov data-breach notice PDF is retained as an older direct public notice-letter boundary. 11-Aug-2026 · Newly retained (>24h) PDF text re-review adds the notice's public data-category and system-boundary language. | Adds and refines one organization-specific boundary: Betterment's notice says Klue Labs Inc. was a vendor used by its sales team with access to a Salesforce database containing Betterment data, unauthorized access involved a file containing name and Social Security number, Betterment's computer systems were not accessed, and Betterment offered two years of Kroll identity monitoring; the brief does not infer impact beyond that public notice boundary. | 80 |
8-Incident Response Playbook Ideas
| Phase | Playbook Idea | Likely Owner | Sources |
|---|---|---|---|
| Immediate scoping | Identify whether Klue, Klue Battlecards, or related Klue Salesforce connected apps were installed, active, or previously authorized. | Salesforce Admin / SaaS Owner | 1,5,6,13 |
| Preserve evidence | Retain Salesforce Event Monitoring, LoginHistory, Connected App OAuth Usage, API logs, Setup Audit Trail, Klue notices, and CRM-object export evidence. | SOC / IR | 5,6 |
| Containment | Revoke Klue OAuth tokens, rotate integration credentials/secrets, disable unneeded Klue integrations, and re-authorize only after scope is understood. | IAM / Salesforce Admin | 1,5,6 |
| Impact analysis | Scope account, contact, lead, opportunity, notes, activity, and custom-object data queried through the connected app during the exposure window. | IR / Legal / Business App Owner | 5,6,7 |
| Notification planning | Separate customer-data exposure, product-system compromise, vault/secret compromise, and customer phishing/social-engineering risk in stakeholder messaging. | Legal / Privacy / Communications | 3,4,30 |
| Firm / sector notification hygiene | 29-Jun-2026 · Newly retained (>24h) For regulated financial-services or member-firm environments, align Klue/Salesforce containment with FINRA's sector guidance: revoke tokens, investigate Salesforce logs, rotate exposed secrets, monitor suspicious outreach, and brief privacy, legal, and vendor-risk owners. | Legal / Compliance / SOC | 53 |
| Vendor re-enablement evidence | 02-Jul-2026 · Freshly reported (<24h) Before restoring Klue integrations, request evidence for GitHub PAT disablement, OAuth credential rotation, integration-service code review, GKE pod containment (disabling affected Google Kubernetes Engine runtime workloads), CrowdStrike/EDR monitoring, SIEM logging, secret scanning, and CI/CD workflow hardening. 30-Jul-2026 · Newly retained (>24h) Klue now says Salesforce and Gong integrations were reinstated after CrowdStrike review; re-enablement should still validate static egress IP allowlisting, platform-wide PKCE, tightened OAuth token lifecycle policies, centralized monitoring, runtime network filtering, and deployment-pipeline allowlist controls. 31-Jul-2026 · Freshly reported (<24h) Also request evidence for organization-wide GitHub PAT blocking, migration to GitHub Apps or workload identity, source verification, runner restrictions, default-deny deployment networking, refresh-token rotation or idle expiration, IP-range allow-listing, and dedicated low-privilege integration accounts where supported. | Vendor Risk / IAM / Salesforce Admin | 59,74,75 |
| Cross-campaign OAuth hardening | 13-Jul-2026 · Freshly reported (<24h) Use Microsoft's broader ShinyHunters-associated SaaS OAuth research to audit trusted connected apps beyond Klue: consent grants, app privileges, refresh-token persistence, Salesforce event monitoring, and guest-access paths. | IAM / Salesforce Admin / SOC | 66 |
Salesforce Forensic View For Klue Attribution
A Klue investigation should not stop at vendor notification. The strongest internal evidence is the convergence of Salesforce connected-app state, OAuth/token activity, EventLogFile records, API query behavior, and object-level access during the reported exposure window.
| Salesforce Evidence | What To Collect | Why It Matters For Klue Attribution | Sources |
|---|---|---|---|
| Connected app / OAuth inventory | Klue, Klue Battlecards, integration users, OAuth policies, authorized users, scopes, token state, last-used timestamps, and whether access was revoked or reauthorized. | This ties the investigation to the trusted Salesforce app path instead of treating the incident as generic account compromise. | 1,5,6,13 |
| EventLogFile / Event Monitoring | REST API, API Total Usage, Bulk API, Login, Report, Report Export, and permission-related event categories where licensed and retained. | EventLogFile is the main Salesforce telemetry path for API use, object access, reports, login behavior, and suspicious operational patterns. | 6,25,26 |
| REST API query evidence | URI, method, user, connected-app context, source IP, user agent, query/queryMore behavior, pagination, object names, and high-volume access to Accounts, Contacts, Leads, Opportunities, Cases, Tasks, Notes, or custom objects. | Klue attribution is strongest when the Klue app or token context lines up with abnormal Salesforce API activity during the incident window. | 5,6,25,26 |
| Global Describe / API-version deviation | 26-Jun-2026 · Newly retained (>24h) Salesforce Global Describe calls, REST API version shifts such as v64.0-to-v59.0 deviation, QueryMore pagination bursts, and user-agent changes from stable Klue baselines. | Obsidian reports these deviations across impacted organizations; they help separate normal integration behavior from reconnaissance and bulk export patterns. | 37 |
| Login History and Login Event data | Who logged in, when, from where, authentication method, failed/successful logins, and whether activity belongs to a human user, integration user, or app-backed session. | This separates direct user compromise from token-backed or connected-app activity and helps build the timeline. | 25,26,28 |
| Setup Audit Trail | Connected-app changes, OAuth policy changes, profile or permission changes, package changes, event-monitoring setting changes, and administrative activity around the exposure window. | Administrative changes can explain blast radius, cleanup actions, or attacker attempts to modify access. | 26,27 |
| Klue attribution test | Look for convergence: Klue connected app or token context, matching incident window, source infrastructure or user-agent clues from research, Salesforce API volume, and accessed CRM objects. | No single string proves Klue attribution; the strongest case is a correlated body of Salesforce and vendor evidence. | 1,5,6 |
| Vendor integration-service control plane | 02-Jul-2026 · Freshly reported (<24h) Klue/CrowdStrike evidence for compromised GitHub PATs, unauthorized integration-service code, affected GKE pods, OAuth credential rotation, EDR/Falcon coverage, SIEM integration, secret scanning, and GitHub Actions allowlisting. | Klue's primary update moves reauthorization due diligence beyond Salesforce logs alone and into the vendor's source-control, CI/CD, cloud-runtime, and monitoring controls. | 59 |
| Sector alert indicators | 29-Jun-2026 · Newly retained (>24h) FINRA-published suspicious IP and sender-domain leads associated with the Klue alert, treated as enrichment for Salesforce/Klue investigations rather than a universal blocklist. | FINRA adds sector-facing IOCs and response guidance; validate sightings against local connected-app, Salesforce API, and email telemetry before attribution. | 53 |
| OAuth-abuse cluster correlation | 13-Jul-2026 · Freshly reported (<24h) Microsoft-described Salesforce/SaaS OAuth-abuse patterns: trusted OAuth relationships, connected-app attribution, inherited application privileges, CRM enumeration/querying, and near-real-time event-monitoring visibility. | This helps teams hunt the broader playbook without over-attributing Klue to a different actor label solely because the tradecraft overlaps ShinyHunters-associated campaigns. | 66 |
9-Term Glossary
| Term | Meaning Here | Sources |
|---|---|---|
| Klue | A competitive enablement / market-intelligence SaaS platform with Salesforce integration use cases. | 5,6 |
| Competitive enablement | A sales and revenue-operations industry term for giving sellers structured competitor intelligence, positioning, objection handling, win/loss lessons, and deal guidance. It is not a formal cybersecurity standard term. | 5,6 |
| Battlecard | A short sales enablement artifact that helps a seller compete in a deal. It may include competitor comparisons, differentiators, pricing or feature notes, objection responses, talk tracks, and account strategy. In a Salesforce investigation, battlecard sync can matter because it may sit near account, opportunity, note, and customer/prospect context. | 5,6 |
| Win/loss analysis | A revenue-team process for documenting why deals were won or lost. It can contain customer feedback, competitor references, sales-stage notes, account strategy, pricing pressure, and relationship context that may be sensitive in a CRM exposure. | 5,6 |
| Connected app | A Salesforce application trust relationship that can use OAuth-style authorization and API access. | 13 |
| OAuth token / refresh token | Authorization material that can let an app access Salesforce resources without repeatedly asking for a password. Refresh-token use is especially important because it can preserve app-backed access until revoked or expired. | 1,5,6 |
| GitHub PAT | GitHub personal access token: a credential string used by a person, script, or integration to authenticate to GitHub without an interactive login. In this incident, Klue's CrowdStrike summary says a previously compromised PAT was used to introduce unauthorized integration-service code. | 59 |
| GKE pod containment | GKE means Google Kubernetes Engine. A pod is a running workload unit; containment means disabling affected runtime pods so suspect integration-service code could no longer run while credentials were rotated. | 59 |
| EventLogFile | Salesforce object used for Event Monitoring data. Forensicators use it to inspect event categories such as REST API, API usage, login, report, report export, and other operational activity depending on licensing and retention. | 25,26 |
| Setup Audit Trail | Salesforce administrative-change history. It can help identify connected-app, permission, profile, package, policy, and configuration changes around the exposure window. | 27 |
| Login History | Salesforce login metadata that helps separate human-user logins from integration or app-backed access patterns when correlated with OAuth and EventLogFile records. | 26,28 |
| CRM objects | Salesforce records such as Accounts, Contacts, Leads, Opportunities, Cases, Tasks, Notes, Events, and custom objects. These are the practical data-scoping targets after token-backed API activity. | 5,6,25,26 |
| Supply-chain attack | A downstream impact path through a trusted third party or integration rather than only a direct attack against the final victim. | 1,14 |
10-TTPs
| Technique / TTP | MITRE ATT&CK ID | Source-Backed Detail | Sources |
|---|---|---|---|
| Trusted third-party integration abuse | T1199: Trusted Relationship | Klue's trusted Salesforce integration created a downstream path into customer CRM environments. | 1,5,6,14 |
| OAuth token theft / reuse | T1528: Steal Application Access Token | Public technical reporting centers on OAuth tokens and refresh-token-backed access to connected Salesforce data. | 1,5,6,15 |
| Valid connected-app access | T1078: Valid Accounts | A trusted integration/service-account style path can make access look legitimate until API behavior or token use is reviewed. | 5,6,16 |
| Cloud application integration abuse | T1671: Cloud Application Integration | 13-Jul-2026 · Freshly reported (<24h) Microsoft maps similar Salesforce OAuth-abuse activity to connected-app integration abuse, reinforcing that SaaS app grants can become persistence and access paths. | 66 |
| Automated Salesforce collection | T1119: Automated Collection | Researchers describe automated Salesforce REST API queries and object access that should be validated against EventLogFile and API telemetry. | 5,6,29 |
| Cloud/API exfiltration | T1567.002: Exfiltration to Cloud Storage | Researchers describe automated Salesforce REST API queries and large-volume CRM data access; map exact behavior to local telemetry before labeling exfiltration. | 5,6,17 |
11-Common Questions Q&A
| Question | Answer | Sources |
|---|---|---|
| Was Salesforce itself exploited? | No source used here establishes a Salesforce platform vulnerability. The stronger framing is abuse of a trusted third-party connected app and OAuth relationship through Klue. | 1,2,5,6 |
| What should a customer check first? | Identify whether Klue or Klue Battlecards was connected to Salesforce, preserve relevant Salesforce logs, review connected-app state, revoke and rotate tokens, and scope object-level API access. | 1,5,6,25,26 |
| Does LastPass mean vault compromise? | No. LastPass described a Klue-linked customer-data incident while stating its product systems, services, infrastructure, and vault data were not compromised. | 3,4,30 |
| Can one victim notice define every impact? | No. Public notices are useful scoping examples, but exact data categories, product-system boundaries, and notification obligations differ by organization and must be tied to local Salesforce evidence. | 7,11,12,32,33,34,35,38,39,40,41,42,43 |
| Does Microsoft now attribute Klue to ShinyHunters or Storm-3138? | 13-Jul-2026 · Freshly reported (<24h) Not as a simple replacement label. Microsoft places Klue-related Salesforce/OAuth abuse in a broader ShinyHunters-associated tradecraft discussion. 18-Jul-2026 · Newly retained (>24h) It also names Storm-3138 for Klue system access, which improves detection and deconfliction, but the Klue brief should still keep Icarus/ICARUS as the Klue-specific public extortion/operator label unless a reliable source directly merges or replaces the activity. | 66 |
12-CVE / Vulnerability References
No CVE, KEV entry, or Salesforce platform vulnerability is established by this source set. The incident is best framed as third-party SaaS integration compromise and OAuth/connected-app abuse. If later sources publish a CVE, Salesforce platform advisory, or official KEV entry, this card should be revised. 1,2,5,6
13-IOCs / Observables
| IOC / Observable Type | Indicator / Lead | What To Hunt / Collect | Sources |
|---|---|---|---|
| Connected app | Klue / Klue Battlecards connected application, OAuth usage, or app-level access to Salesforce. | List connected apps, OAuth policies, refresh-token use, scopes, last-used timestamps, and authorized users. | 5,6,13 |
| OAuth token | OAuth refresh-token usage or new token activity tied to Klue integration accounts. | Review Salesforce OAuth usage events and revoke tokens before reauthorization. | 1,5,6 |
| API behavior | High-volume Salesforce REST API query or QueryMore behavior from connected-app context. | Correlate unusual query volume, object enumeration, large result pagination, and unfamiliar source IPs. | 5,6 |
| Salesforce reconnaissance / API behavior | 26-Jun-2026 · Newly retained (>24h) Global Describe object catalog queries, `/services/data/v59.0/query` and QueryMore pagination, API-version downgrade, and deviation from expected Klue infrastructure or user-agent baselines. | Pair these with Klue connected-app context and tenant-specific object access; do not treat any single string as deterministic without correlated Salesforce evidence. | 37 |
| FINRA sector-alert IOCs | 29-Jun-2026 · Newly retained (>24h) FINRA published suspicious IP addresses and sender-domain leads tied to its Klue alert; ZeroFox also published ICARUS-related indicators and infrastructure references. | Use as enrichment only. Do not publish raw victim data or infer universal applicability without Klue connected-app context, Salesforce evidence, and local email/network telemetry. | 53,54 |
| Microsoft Klue IOC context | 13-Jul-2026 · Freshly reported (<24h) Microsoft lists 138.226.246.94 as an IP address used by the Klue integration to call the Salesforce API for CRM queries on June 11, noting it was previously disclosed by Klue. | Treat this as corroborating enrichment. Correlate with Klue connected-app context, Salesforce API events, source IP, user agent, and object access before drawing customer-specific impact conclusions. | 66 |
| User agent | Python-style automation strings reported in technical analysis. | Treat as supporting signal only; correlate with Klue app, token use, API volume, and source infrastructure. | 5,6 |
| LastPass-published IOCs | LastPass published a small appendix of source IP addresses and email sender domains associated with its response. | Treat these as LastPass-context indicators: collect sightings, correlate with Salesforce/Klue evidence, and do not assume universal Klue applicability without local telemetry. | 30 |
| Boundary | This brief does not publish a stable blocklist of domains, hashes, or customer-specific record IDs. | Use environment-specific Salesforce logs and official Klue/customer notifications for deterministic scoping. | 1,6 |
14-Threat Actor Glossary
29-Jun-2026 · Newly retained (>24h) Icarus/ICARUS is the public actor label tied to the Klue-linked extortion/data-theft activity in this source set, but the evidence still does not support treating it as fully resolved attribution. FINRA and ZeroFox reinforce the label and add sector/actor context; ZeroFox also flags Underground Uwu / Scattered Lapsus$ Hunters claims as caveated context. Keep UNC6395 and Salesloft Drift as Salesforce OAuth-abuse comparator context unless a reliable source explicitly merges the Klue activity with that campaign.13-Jul-2026 · Freshly reported (<24h) Microsoft now adds a broader ShinyHunters-associated SaaS OAuth-abuse lens; use it for tradecraft and detection context, not as a standalone instruction to relabel Klue from Icarus to ShinyHunters. 18-Jul-2026 · Newly retained (>24h) Microsoft's Storm-3138 label should be tracked as a source-backed activity label for Klue system access, not as a reason to erase the Icarus/ICARUS extortion/operator boundary. 5,6,36,37,53,54,66
| Actor / Activity Label | Meaning In This Brief | Attribution Boundary | Sources |
|---|---|---|---|
| Icarus / ICARUS | 29-Jun-2026 · Newly retained (>24h) Public actor label associated with Klue-linked data theft/extortion claims and Salesforce OAuth-abuse reporting; FINRA and ZeroFox reinforce the Icarus/ICARUS naming. | Use as the current Klue-linked label, not as a final attribution or proof of shared infrastructure with other Salesforce campaigns. | 5,6,36,37,53,54 |
| Underground Uwu / SLH claims | 29-Jun-2026 · Newly retained (>24h) ZeroFox notes public claims involving Underground Uwu and Scattered Lapsus$ Hunters in connection with ICARUS activity. | Use as caveated actor-claim context only. Do not collapse it into UNC6395/Salesloft Drift or customer-impact conclusions without stronger evidence. | 54 |
| Storm-3138 | 18-Jul-2026 · Newly retained (>24h) Microsoft names Storm-3138 as the activity label tied to Klue system access in its July 13 Salesforce/SaaS OAuth abuse research. | Use as Microsoft's activity label for the Klue system-access path. Do not treat it as proof that Klue/Icarus, UNC6395, Salesloft Drift, Gainsight, and ShinyHunters are one merged campaign. | 66 |
| ShinyHunters-associated SaaS OAuth abuse | 13-Jul-2026 · Freshly reported (<24h) Microsoft describes a series of Salesforce/SaaS campaigns observed from mid-2025 to mid-2026 with overlapping tradecraft commonly associated with ShinyHunters, including trusted OAuth relationship abuse, supply-chain compromise, and CRM querying. | Use as broader tradecraft and detection context. Do not use this row alone to collapse Klue/Icarus into UNC6395, Salesloft Drift, Gainsight, or a definitive ShinyHunters attribution. | 66 |
| UNC6395 / Salesloft Drift | Closest public Salesforce OAuth supply-chain comparator: stolen or abused SaaS integration tokens leading to downstream Salesforce data exposure. | Comparator only. Current Klue source set does not merge Klue/Icarus with UNC6395 or the Salesloft Drift campaign. | 18,19,20,21,22,23,24,37 |
15-Talking Points
| Audience | Talking Point | Memorizable Quote |
|---|---|---|
| Executive | This is a Salesforce-data supply-chain issue through a trusted SaaS integration. The question is not only whether Klue was breached; it is whether our Salesforce data was reachable through Klue's OAuth relationship. | “We should treat this like a cloud identity and vendor-access event. If Klue had token-backed access into our Salesforce org, we need to know what objects were reachable, what was queried, and whether customer or prospect data requires notification.” |
| Salesforce Admin | Focus on connected apps, OAuth tokens, REST API query volume, and Klue Battlecards activity. | “Our fastest path to clarity is Salesforce telemetry: connected-app usage, OAuth refresh-token events, REST API queries, source IPs, user agents, and object-level access during the Klue exposure window.” |
| Legal / Privacy | Separate confirmed product compromise from CRM data exposure. | “A downstream customer can be affected even if its own systems were not breached. The legal question is what Salesforce records were accessed through the vendor integration and whether those records include personal, customer, or confidential commercial data.” |
| Client / Claims Scoping | Ask whether the client used Klue or Klue Battlecards, not just whether they received a direct breach notice. | “For scoping, we should collect Klue notices, Salesforce connected-app inventory, token revocation evidence, and API logs. If the integration existed, we need to validate whether access occurred and whether the exposed data changes notification or fraud risk.” |
| Threat Intel | 13-Jul-2026 · Freshly reported (<24h) Microsoft adds ShinyHunters-associated OAuth-abuse tradecraft context, not a definitive replacement of the Klue/Icarus public actor label. | “We should use Microsoft’s research to broaden detection and deconfliction, while keeping Klue-specific attribution language disciplined: Icarus remains the public label in this brief unless direct evidence merges it with another cluster.” |
16-Decision Ready Actions
| Target Persona | Timeframe | Decision / Action | Evidence |
|---|---|---|---|
| Executives | Today | Treat this as SaaS supply-chain CRM exposure, not a password-only incident. | 1,3,4,5 |
| Salesforce owners | Today | Inventory Klue integrations, revoke tokens, and re-authorize only with least privilege and monitoring. | 1,5,6,13 |
| Legal / privacy | 24-48 hours | Determine whether Salesforce objects accessed contain personal data, customer contacts, commercial terms, notes, or regulated data. | 3,6,7 |
| SOC / IR | 24-48 hours | Preserve Salesforce logs and hunt for token/API activity before cleanup obscures timeline. | 5,6 |
| Vendor-risk teams | This week | Update SaaS integration inventories and require vendors to document token revocation, least privilege, and breach notification paths. | 1,2,5 |
| Threat intel / detection | This week | 13-Jul-2026 · Freshly reported (<24h) Track Klue as part of a broader Salesforce/SaaS OAuth-abuse playbook associated with ShinyHunters tradecraft. 18-Jul-2026 · Newly retained (>24h) Track Storm-3138 as Microsoft's Klue system-access activity label while keeping Icarus/ICARUS as the Klue-specific public extortion/operator label unless stronger evidence appears. | 66 |
17-Exploitable Technology Risks
| Technology / Trust Risk | Why It Matters | Defensive Priority | Sources |
|---|---|---|---|
| Over-permissioned connected apps | A third-party integration can access more Salesforce data than the business workflow actually needs. | Review scopes, user mappings, OAuth policies, and connected-app least privilege. | 5,6,13 |
| Long-lived OAuth refresh tokens | Tokens can persist beyond a single user login and provide durable API access. | Revoke tokens, shorten session/token policy where possible, and alert on unusual refresh-token usage. | 1,5,6 |
| CRM data concentration | Salesforce often contains prospects, customer contacts, commercial notes, account strategy, and opportunity data. | Classify high-risk objects and run object-level access/export scoping after integration abuse. | 5,6,7 |
| Third-party blast radius | A single SaaS vendor can create exposure across many customers when it holds trusted integration credentials. | Track critical SaaS vendors as privileged access paths, not just procurement records. | 1,5,6 |
| Reusable OAuth-abuse tradecraft | 13-Jul-2026 · Freshly reported (<24h) Microsoft describes trusted OAuth abuse across Salesforce/SaaS campaigns observed from mid-2025 to mid-2026, with overlap commonly associated with ShinyHunters. | Monitor connected-app attribution, app permissions, OAuth consent grants, CRM querying, and persistence signals across all high-trust SaaS integrations. | 66 |
19-Tier 0 Through Tier 8 Source Summary
| Tier | Trust Role | What This Tier Supports | Caveat | Sources |
|---|---|---|---|---|
| Tier 0 | Primary / official | 02-Jul-2026 · Freshly reported (<24h) Klue's CrowdStrike update adds the strongest primary mechanism and containment evidence: compromised GitHub PAT (personal access token), unauthorized integration-service code, Salesforce OAuth token collection, GKE pod containment, no identified access outside integration-service-related systems, no activity after June 12, and CI/CD/security hardening. 30-Jul-2026 · Newly retained (>24h) Klue's restoration update adds the primary re-enablement milestone and new control claims for Salesforce/Gong marketplace reinstatement, static egress IP allowlisting, platform-wide PKCE, OAuth-token lifecycle tightening, GitHub PAT elimination, centralized monitoring, runtime network filtering, and deployment-pipeline allowlisting. 31-Jul-2026 · Freshly reported (<24h) Klue's CTO post adds the freshest primary engineering narrative for GitHub source-code access, second PAT discovery, credential testing, build/deployment abuse, stored OAuth-token access, and durable credential, CI/CD, OAuth, and evidence-sharing lessons. LastPass, Salesforce, and 8x8 provide downstream and platform boundaries. | Official sources do not publish every downstream customer, object count, or full actor attribution; restoration and CTO lessons should be treated as control evidence to validate, not proof that every customer should re-enable without tenant-specific review. | 1,2,3,30,40,59,74,75 |
| Tier 1 | Starter news | BleepingComputer ties LastPass confirmation to the Klue supply-chain story and gives broad public awareness context. | Secondary to primary notices for product-system and vault-status claims. | 4 |
| Tier 2 | Technical research | 29-Jun-2026 · Newly retained (>24h) ReliaQuest, Datadog, Huntress, Obsidian, and ZeroFox provide mechanism, timeline, OAuth/API hunting, Global Describe/API-version/user-agent deviations, Icarus/ICARUS context, and downstream impact context. 13-Jul-2026 · Freshly reported (<24h) Microsoft adds broader ShinyHunters-associated Salesforce/SaaS OAuth-abuse tradecraft, connected-app visibility guidance, and Klue IOC context. 18-Jul-2026 · Newly retained (>24h) Microsoft's Storm-3138 label is retained as an activity label for Klue system access. | Use local telemetry to confirm exact objects, records, indicators, and exposure per tenant. Microsoft strengthens tradecraft deconfliction but does not by itself replace the Klue-specific Icarus/ICARUS public extortion/operator label. | 5,6,7,37,54,66 |
| Tier 3-4 | Corroboration / customer signal | 29-Jun-2026 · Freshly reported (<24h) AudienceView adds a fresh status-resolution timestamp. 02-Jul-2026 · Newly retained (>24h) Trade coverage and customer trust-center notices help show spread, downstream notification patterns, second-wave extortion pressure, and public customer disclosure boundaries; Camunda now narrows its own boundary to standard business-contact and account information, excluding support data. 04-Jul-2026 · Newly retained (publication date not visible) AlertMedia, Cresta, Lucanet, ABBYY, and Postman add undated direct trust-center or trust-portal boundaries. 05-Jul-2026 · Newly retained (>24h) Automox adds a direct no-impact Salesforce/OAuth review boundary useful for deconflicting leak-list claims. 07-Jul-2026 · Newly retained (>24h) eSentire adds a direct minimal-exposure customer disclosure with restricted-OAuth and customer-service risk boundaries. 08-Jul-2026 · Newly retained (>24h) Thinkproject adds a UAT CRM-specific Salesforce/Klue customer boundary with product, service, and customer-platform exclusions. 16-Aug-2026 · Newly retained (>24h) Thinkproject later resolves the status incident with its investigation concluded, no known misuse of affected data, and continued monitoring. 09-Jul-2026 · Newly retained (>24h) Snyk adds a Mandiant-assisted investigation-closure boundary. 09-Jul-2026 · Freshly reported (<24h) Secure ISS relays a SentinelOne partner-notification boundary with Salesforce-only impact and no core-product/cloud/production impact reported. 11-Jul-2026 · Newly retained (>24h) OneTrust adds investigation closure, finalized containment/remediation, and no evidence of exposure beyond its Salesforce environment. 14-Jul-2026 · Newly retained (publication date not visible) Sisense adds an undated direct trust-center boundary for business and sales-related Salesforce CRM data while excluding Sisense product-platform data. 16-Jul-2026 · Newly retained (>24h) Qualtrics and Splashtop add older direct public customer boundaries for Salesforce data access while preserving platform/product exclusions. 23-Jul-2026 · Newly retained (>24h) Greenhouse and Blackbaud add direct Conveyor trust-center customer boundaries: Greenhouse limits access to business contact information in sales/customer relationship systems and excludes product, hiring, candidate, infrastructure, modification, and deletion impact; Blackbaud reports an ongoing investigation with no substantive update, no known product impact, and no business-operations/customer-service impact. 24-Jul-2026 · Newly retained (publication date not visible) Confluent adds an undated direct trust-center statement limiting copied data to CRM business information and excluding product-processed customer data, products, platform, and infrastructure impact. 28-Jul-2026 · Newly retained (>24h) Autodesk adds an older direct no-impact advisory stating it did not use the Salesforce or Gong integrations for Klue and found no direct impact to Autodesk products, services, or systems. 02-Aug-2026 · Newly retained; undated Yext adds an undated direct SafeBase boundary for read-only Salesforce CRM queries, customer/prospect business-contact exposure, and platform/product/infrastructure/customer-content/end-user-data/payment-card/Google Workspace/Slack exclusions. 03-Aug-2026 · Newly retained (>24h) Commvault and NetDocuments add older rendered trust-center/customer-advisory boundaries for Salesforce business relationship/sales activity data and internal Gong-user staff-list exposure respectively, with customer-data, product/service, backup/log, Customer Repository Data, and NetDocuments Service exclusions. 04-Aug-2026 · Newly retained (>24h) Neon One adds an older direct public notice letter tying unauthorized access to personal information to Klue's Salesforce CRM integration service. 10-Aug-2026 · Newly retained (>24h) Betterment adds an older regulator-hosted notice-letter boundary tying Klue Labs, Betterment's sales team, and a Salesforce database containing Betterment data. 11-Aug-2026 · Newly retained (>24h) PDF text re-review adds Betterment's public name/SSN file language, no-Betterment-systems-access boundary, and two-year Kroll identity-monitoring offer. | Do not treat every named organization as having the same exposure without its own notice; SentinelOne is retained as a public advisory/partner-notification lead because the direct portal reference is access-controlled; OneTrust's governance, compliance, and notification review remains ongoing; Sisense, Confluent, and Yext have no visible publication dates and should not be labeled fresh; Splashtop's investigation remained ongoing at publication; Blackbaud's public notice does not publish data-category detail and points active customers to logged-in FAQ/update material; Autodesk is a no-impact deconfliction notice, not a Salesforce-data-exfiltration example; Commvault and NetDocuments are older rendered public notices newly retained after prior JavaScript-only retrieval failures; Neon One's public sample notice does not disclose the specific personal-information elements; Betterment should not be expanded beyond the notice-letter language for name/SSN, no Betterment computer-system access, and Kroll identity monitoring. | 8,9,10,11,12,31,32,33,34,35,36,38,39,41,42,43,44,45,46,47,48,49,50,51,52,55,56,57,58,60,61,62,63,64,65,67,68,69,70,71,72,73,76,77,78,79,80 |
| Tier 5 | Framework / documentation | 29-Jun-2026 · Newly retained (>24h) Salesforce docs, MITRE ATT&CK, and FINRA sector guidance help explain connected-app trust, EventLogFile forensics, login/setup audit data, token theft, trusted relationships, valid-account behavior, automated collection, exfiltration mapping, IOCs, and response priorities. | Framework and sector guidance support scoping; they do not prove tenant impact. Salesforce log availability depends on edition, licensing, retention, and tenant configuration. | 13,14,15,16,17,25,26,27,28,29,53 |
| Tier 8 | Expansion research | Salesloft Drift sources provide the closest prior Salesforce OAuth supply-chain comparator: a trusted SaaS integration, stolen OAuth tokens, downstream Salesforce data theft, and tenant-specific revocation/scoping. | Drift is a comparator, not evidence that Klue and Drift share the same actor, infrastructure, or campaign window. | 18,19,20,21,22,23,24 |
20-Source Reconciliation
| Source Issue | Agreement / Difference | Tension or Contradiction | How To Use It |
|---|---|---|---|
| Salesforce platform boundary | No public source used here establishes a Salesforce platform vulnerability. The strongest framing is third-party OAuth/connected-app abuse through Klue. | A CRM data exposure can be misread as a Salesforce core exploit. | Focus teams on integration tokens, connected apps, Salesforce logs, and CRM scoping. 1,2,5,6 |
| Root-cause mechanism refinement | 02-Jul-2026 · Freshly reported (<24h) Klue's CrowdStrike summary refines the path: a previously compromised GitHub PAT introduced unauthorized code into Klue's integration service, which collected third-party integration credentials including Salesforce OAuth access and refresh tokens. 31-Jul-2026 · Freshly reported (<24h) Klue's CTO post adds a two-phase GitHub and CI/CD narrative: source-code download, additional PAT discovery, credential testing, build/deployment abuse, tampered production workload, and stored OAuth-token access. | Earlier shorthand about a legacy integration credential remains useful for token-exposure scoping but is no longer the most precise root-cause language. | Use the PAT/code/deployment path for root-cause and vendor-control discussions; use OAuth/connected-app language for downstream Salesforce tenant scoping. 1,5,6,59,75 |
| Engineering and vendor-control lessons | 31-Jul-2026 · Freshly reported (<24h) Klue now frames GitHub and CI/CD as part of the production security boundary and says durable improvements include blocking GitHub PATs, migrating to GitHub Apps or workload identity, strengthening source verification, secret scanning, deployment protections, runner restrictions, default-deny network controls, centralized monitoring, stronger OAuth controls, and reducing long-lived credential reliance. | These lessons strengthen reauthorization diligence but do not add a new public victim, prove a Salesforce platform vulnerability, or resolve actor attribution. | Convert the CTO post into vendor-risk evidence requests and internal SaaS-integration hardening checks; keep customer impact and attribution conclusions tied to direct customer notices and telemetry. 75 |
| Integration restoration and reauthorization | 30-Jul-2026 · Newly retained (>24h) Klue says Salesforce and Gong reinstated Klue integrations in their marketplaces and that all Klue integrations are again available for customers to enable after CrowdStrike review and added controls. | Marketplace reinstatement changes availability and vendor-control posture, but it does not erase each customer's obligation to validate tenant-specific scope, token state, least privilege, and exposure window findings before reauthorization. | Treat this as a controlled re-enablement milestone: validate the specific controls Klue names and document customer-side connected-app owner, scopes, token lifecycle, monitoring, and reauthorization decision. 74 |
| LastPass impact boundary | LastPass says its product systems, services, infrastructure, and vaults were not compromised; the issue was customer/CRM data tied to Klue/Salesforce. | Public headlines can overstate this into a LastPass vault compromise. | Separate CRM/customer-record exposure from password-vault or product-system compromise, while still treating exposed contact and support data as phishing/social-engineering risk. 3,4,30 |
| Salesloft Drift comparison | Drift is the strongest prior Salesforce OAuth supply-chain comparator: trusted SaaS integration access became the path to downstream Salesforce data. | The comparator can be mistaken for shared actor, infrastructure, or campaign timing. | Use Drift to guide scoping questions, not attribution. 18,19,20,21,22,24 |
| Actor identity | 29-Jun-2026 · Newly retained (>24h) Icarus/ICARUS is the public actor label tied to Klue in this source set; FINRA and ZeroFox reinforce the label, while ZeroFox caveats Underground Uwu / Scattered Lapsus$ Hunters references and Obsidian keeps Klue/Icarus separate from UNC6395/Salesloft Drift except as pattern comparison. 13-Jul-2026 · Freshly reported (<24h) Microsoft places Klue-adjacent OAuth abuse inside broader Salesforce/SaaS tradecraft commonly associated with ShinyHunters. 18-Jul-2026 · Newly retained (>24h) Microsoft names Storm-3138 for the Klue system-access path, adding a source-backed activity label without proving that Icarus/ICARUS, UNC6395, Salesloft Drift, and ShinyHunters are one campaign. | Shared Salesforce OAuth-abuse tradecraft and public actor claims can be mistaken for shared operators or merged labels. | Use Storm-3138 as Microsoft's activity label for Klue system access, use Icarus/ICARUS for the Klue-linked extortion/data-theft label, keep Underground Uwu/SLH as caveated actor-claim context, keep UNC6395/Salesloft Drift as comparator context, and use Microsoft to broaden ShinyHunters-associated tradecraft hunting unless stronger attribution evidence appears. 5,6,36,37,53,54,66 |
| Affected-customer boundary | 28-Jun-2026 · Newly retained (>24h) Downstream customers using impacted Klue/Salesforce or Klue-connected integration paths may need to scope exposure; published notices vary by organization, and direct OneTrust, Gong, and Insurity notices reinforce that impact boundaries are organization-specific. 11-Jul-2026 · Newly retained (>24h) OneTrust now states its technical investigation, containment, and remediation are complete, with no evidence of exposure beyond its Salesforce environment. | Not every Klue customer necessarily had the same exposure or data access; investigation closure for one customer does not close another customer's scope. | Make customer-specific statements from notices and local Salesforce telemetry only. 1,7,11,12,32,33,34,35,36,38,39,40,41,42,43,44,45,46 |
| Follow-on extortion pressure | Fresh reporting says Klue told customers the original criminals were deleting stolen data while a second group was making threats. | Second-group possession, completeness, and proof may vary by customer and should not be assumed without direct evidence. | Treat follow-on contact as an extortion/scoping lead: preserve communications, demand proof before conclusions, and coordinate legal and law enforcement. 31 |
| Expanded public disclosures | 29-Jun-2026 · Freshly reported (<24h) AudienceView adds a fresh status-resolution timestamp for a Klue-Salesforce integration notice. 02-Jul-2026 · Newly retained (>24h) Link11, ControlUp, Deel, Saviynt, and Camunda add or refine direct CRM, sales-data, Salesforce-data, or business-contact/account notice boundaries. 04-Jul-2026 · Newly retained (publication date not visible) AlertMedia, Cresta, Lucanet, ABBYY, and Postman remain undated direct trust-center or trust-portal boundaries. 07-Jul-2026 · Newly retained (>24h) eSentire adds a dated direct customer disclosure with minimal Salesforce exposure and explicit exclusions for customer communications, support interactions, threat intelligence, telemetry, credentials, passwords, and payment-card data. 08-Jul-2026 · Newly retained (>24h) Thinkproject adds a dated direct status notice for a UAT CRM environment exposure boundary. 16-Aug-2026 · Newly retained (>24h) Thinkproject's Aug. 12 resolution adds investigation closure and no known misuse of affected data without expanding the UAT CRM boundary. 09-Jul-2026 · Newly retained (>24h) Snyk adds an investigation-complete boundary. 09-Jul-2026 · Freshly reported (<24h) Secure ISS adds a public SentinelOne advisory lead. 11-Jul-2026 · Newly retained (>24h) OneTrust adds investigation-complete and Salesforce-only exposure-boundary language. 14-Jul-2026 · Newly retained (publication date not visible) Sisense adds a direct undated trust-center boundary for business and sales-related Salesforce CRM data, excluding product-platform data. 16-Jul-2026 · Newly retained (>24h) Qualtrics and Splashtop add direct older Salesforce/Klue notice boundaries with product/platform exclusions. 23-Jul-2026 · Newly retained (>24h) Greenhouse and Blackbaud add direct Conveyor trust-center boundaries with organization-specific impact language. 24-Jul-2026 · Newly retained (publication date not visible) Confluent adds a direct undated trust-center boundary for CRM business information while excluding Confluent product-processed customer data, products, platform, and infrastructure impact. 28-Jul-2026 · Newly retained (>24h) Autodesk adds a direct no-impact trust-center boundary after investigating the Klue notification. 03-Aug-2026 · Newly retained (>24h) Commvault and NetDocuments add rendered older public notices after prior JavaScript-only checks; each narrows its own boundary rather than changing the universal Klue impact model. 04-Aug-2026 · Newly retained (>24h) Neon One adds a direct public notice letter tying unauthorized access to personal information to Klue's Salesforce CRM integration service. 10-Aug-2026 · Newly retained (>24h) Betterment adds a regulator-hosted notice-letter boundary tying Klue Labs, Betterment's sales team, and a Salesforce database containing Betterment data. 11-Aug-2026 · Newly retained (>24h) Betterment PDF text re-review adds public name/SSN, no-Betterment-computer-system-access, and Kroll identity-monitoring boundaries. | The exact data categories and business impact differ by organization; Camunda's latest notice narrows, rather than expands, its support-data boundary, Postman excludes customer data access from Gong while confirming Salesforce exfiltration, eSentire limits exposure to standard business contact and sales metadata fields, Thinkproject confines its public boundary to UAT CRM business-contact/commercial information and later says its investigation concluded with no known misuse, Snyk closes on business CRM data, SentinelOne data analysis remains ongoing, OneTrust's governance/compliance review remains ongoing, Sisense and Confluent have no visible publication dates, Splashtop's investigation remained ongoing, Greenhouse excludes product/hiring/candidate/infrastructure impact, Blackbaud publishes no public data-category detail while its investigation remains ongoing, Autodesk reports no Salesforce/Gong integration use, Commvault excludes customer data and product/service/backup/log impact, NetDocuments excludes customer, prospect, Customer Repository Data, and service impact, Neon One does not publish the specific personal-information elements in its sample notice, and Betterment should not be expanded beyond the notice-letter language for name/SSN, no Betterment computer-system access, and Kroll identity monitoring. | Use named notices as scoping examples, not as a universal victim impact template. Treat SentinelOne as qualified until a public direct notice is accessible; treat Sisense and Confluent as newly retained undated, not fresh; treat Qualtrics, Splashtop, Greenhouse, Blackbaud, Autodesk, Commvault, NetDocuments, Neon One, and Betterment as newly retained older disclosures; treat Thinkproject's Aug. 12 closure as a resolution update to an existing UAT CRM example, not a new exposure category; treat Blackbaud as an ongoing-investigation/no-known-product-impact notice rather than confirmed data-category exposure; treat Autodesk and NetDocuments as no customer-data/service-impact deconfliction examples; do not infer Neon One data elements beyond the notice letter or Betterment impact beyond the notice-letter name/SSN, no-computer-system-access, and identity-monitoring boundary. 32,33,34,35,36,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,55,56,57,58,60,62,63,64,65,67,68,69,70,71,72,73,77,78,79,80 |
| Yext disclosure boundary | 02-Aug-2026 · Newly retained; undated Yext says stolen Klue-held credentials were used to run read-only queries against Yext's internal Salesforce CRM for roughly 17 hours on June 11-12 and exposed business contact details for customers and prospects. | Yext is a confirmed Salesforce CRM exposure example, but it should not be generalized into product, infrastructure, end-user-data, or payment-card exposure. | Preserve Yext's exclusions for platform, products, infrastructure, customer content, customer-facing systems, end-user data, payment-card data, Google Workspace, and Slack; treat the source as newly retained undated. 76 |
| Commvault / NetDocuments disclosure boundary | 03-Aug-2026 · Newly retained (>24h) Commvault says accessed data was limited to business relationship and sales activity information in its Salesforce environment; NetDocuments says the Klue incident affected only an internal Gong-user staff list. | Both are confirmed Klue-linked disclosures, but neither should be rewritten as customer repository, backup, product, or service compromise. | Preserve the exclusions: Commvault says no customer data, solutions/services, customer backup data, product metadata, or logs were affected; NetDocuments says no customer data, prospective customer data, Customer Repository Data, or NetDocuments Service impact. 77,78 |
| Leak-list and second-actor claims | 05-Jul-2026 · Newly retained (>24h) Automox says its name appeared on a second threat actor list, but its data was not in the sample, it did not receive Klue CEO outreach to impacted organizations, and Klue confirmed no indication Automox data or customer data was affected. | A named organization in a leak-list or second-actor claim is not the same as confirmed Salesforce exfiltration. | Treat Automox as a direct no-impact/deconfliction example: preserve the lead, validate against Salesforce logs and vendor notice facts, and avoid promoting leak-list-only claims as public victims. 61 |
21-About the Contributors
| Contributor | Who They Are / What They Do | Contribution & Why It Matters Here | Sources |
|---|---|---|---|
| Klue | Primary vendor / integration provider | 02-Jul-2026 · Freshly reported (<24h) Publishes the controlling vendor statements on unauthorized integration-infrastructure activity, the CrowdStrike-refined GitHub PAT and unauthorized integration-service code path, credential/token revocation, integration disabling, monitoring, and security hardening. 30-Jul-2026 · Newly retained (>24h) Adds the primary restoration update for Salesforce/Gong marketplace reinstatement and post-incident controls customers should validate before re-enablement. 31-Jul-2026 · Freshly reported (<24h) Adds a CTO lessons-learned post with fresh engineering detail on the two-phase GitHub/CI-CD intrusion path, stored OAuth-token access, and durable credential, deployment, OAuth, and evidence-sharing controls. | 1,59,74,75 |
| LastPass | Downstream customer | Confirms customer-data impact through Klue, identifies Salesforce/Gong integration context, describes token rotation and discontinued Klue access, and states LastPass product systems and vaults were not compromised. | 3,30 |
| Salesforce | Platform provider | Provides ecosystem framing that the activity is not a Salesforce platform vulnerability and that third-party application trust is central. | 2 |
| OneTrust | Downstream customer boundary update | 11-Jul-2026 · Newly retained (>24h) Adds a July 10 investigation-complete update: technical investigation, scope validation, containment, and remediation are complete; no evidence was found beyond OneTrust's Salesforce environment; governance, compliance, and notification review continue. | 44 |
| ReliaQuest / Datadog / Huntress / Obsidian | Technical researchers and affected defender signal | Add OAuth, REST API, token, timeline, Global Describe, QueryMore, API-version, user-agent, hunt, and downstream-impact detail that turns the story into an actionable IR scoping brief. | 5,6,7,37 |
| BleepingComputer, SecurityWeek, and trade press | Public corroboration | Translate the incident into accessible public risk language and confirm that LastPass and other organizations are responding publicly, including follow-on reporting about public disclosure volume and second-wave extortion pressure. | 4,8,9,10,31,32,36 |
| Postman | Downstream customer | 04-Jul-2026 · Newly retained (publication date not visible) Adds a direct customer boundary for Salesforce customer contact/sales-data exfiltration via Klue, while excluding customer data access from Gong and core platform-services impact. | 60 |
| eSentire | Downstream customer | 07-Jul-2026 · Newly retained (>24h) Adds a direct minimal-exposure Salesforce boundary, restricted-OAuth/limited-connected-app context, customer-service no-risk statement, and exclusions for customer communications, support interactions, threat intelligence, telemetry, credentials, passwords, and payment-card data. | 62 |
| Thinkproject | Downstream customer | 08-Jul-2026 · Newly retained (>24h) Adds a direct UAT CRM exposure boundary, possible business-contact and commercial-information data categories, and exclusions for Thinkproject products, services, and the customer product platform. 16-Aug-2026 · Newly retained (>24h) Adds the Aug. 12 status resolution: investigation concluded, no known misuse of affected data, and continued monitoring. | 63 |
| Sisense | Downstream customer | 14-Jul-2026 · Newly retained (publication date not visible) Adds a direct trust-center boundary for certain business and sales-related Salesforce CRM data, while excluding Sisense product-platform and product-platform data impact. | 67 |
| Qualtrics / Splashtop | Downstream customer boundary updates | 16-Jul-2026 · Newly retained (>24h) Qualtrics adds a direct Salesforce B2B-identifier boundary with Qualtrics platform customer-data exclusion. Splashtop adds a direct Klue/Salesforce OAuth notice with product/service exclusion and ongoing-investigation caveat. | 68,69 |
| Greenhouse / Blackbaud | Downstream customer boundary updates | 23-Jul-2026 · Newly retained (>24h) Greenhouse adds a direct Klue-credential/Salesforce-business-systems boundary with limited business-contact data and product, hiring, candidate, infrastructure, modification, and deletion exclusions. Blackbaud adds an ongoing-investigation update with no substantive update, no known product impact, and no business-operations/customer-service impact. | 70,71 |
| Confluent | Downstream customer boundary update | 24-Jul-2026 · Newly retained (publication date not visible) Adds a direct SafeBase trust-center boundary: copied data was limited to Confluent CRM business information, while product-processed customer data, products, platform, and infrastructure were not impacted according to Confluent. | 72 |
| Autodesk | Downstream customer no-impact boundary | 28-Jul-2026 · Newly retained (>24h) Adds a direct trust-center no-impact boundary: Autodesk says it did not use the Salesforce or Gong integrations for Klue and identified no direct impact to Autodesk products, services, or systems. | 73 |
| Yext | Downstream customer boundary update | 02-Aug-2026 · Newly retained; undated Adds a direct SafeBase trust-center boundary for read-only internal Salesforce CRM queries on June 11-12, customer/prospect business-contact exposure, and platform, product, infrastructure, customer-content, end-user-data, payment-card, Google Workspace, and Slack exclusions. | 76 |
| Commvault / NetDocuments | Downstream customer boundary updates | 03-Aug-2026 · Newly retained (>24h) Commvault adds a rendered Vanta trust-center boundary for Salesforce business relationship and sales activity information with customer-data, product/service, backup-data, product-metadata, and log exclusions. NetDocuments adds a rendered TrustShare advisory limiting impact to an internal Gong-user staff list with customer, prospect, Customer Repository Data, and service exclusions. | 77,78 |
| Betterment / Massachusetts Attorney General Data Breach Notification Portal | Regulator-hosted downstream customer notice | 10-Aug-2026 · Newly retained (>24h) Adds an older public notice-letter boundary: Klue Labs Inc. was a vendor used by Betterment's sales team and had access to a Salesforce database containing Betterment data. 11-Aug-2026 · Newly retained (>24h) PDF text re-review adds that the accessed file contained name and Social Security number, Betterment's computer systems were not accessed, and two years of Kroll identity monitoring were offered. | 80 |
| Microsoft Security Research / Microsoft Defender Security Research Team | Technical research / campaign deconfliction | 13-Jul-2026 · Freshly reported (<24h) Adds broader ShinyHunters-associated Salesforce/SaaS OAuth-abuse tradecraft context, connected-app visibility guidance, MITRE technique mapping, and a Klue integration IP context note for June 11 Salesforce API CRM queries. 18-Jul-2026 · Newly retained (>24h) Adds the Storm-3138 activity label for the Klue system-access path while preserving Icarus/ICARUS as a separate public extortion/operator label. | 66 |
| Snyk / SentinelOne | Downstream customer boundary updates | 09-Jul-2026 · Newly retained (>24h) Snyk adds Mandiant-assisted investigation closure with business-CRM-data-only impact and no Snyk platform impact. 09-Jul-2026 · Freshly reported (<24h) Secure ISS relays a SentinelOne partner-notification boundary: Salesforce-environment-only impact through Klue API integration, no lateral movement, no core-product/cloud/production impact, and ongoing data analysis. | 64,65 |
22-Real World Examples
| Example | What It Shows | Boundary | Sources |
|---|---|---|---|
| Klue integration infrastructure | Klue says unauthorized activity affected part of its integration infrastructure and involved a compromised legacy integration credential that exposed OAuth tokens used to connect Klue with Salesforce and other platforms. 02-Jul-2026 · Freshly reported (<24h) Klue's CrowdStrike summary adds that a previously compromised GitHub PAT introduced unauthorized code into the integration service and collected third-party integration credentials. | This is the upstream supply-chain path. Do not turn it into a Salesforce platform vulnerability or a finding that all Klue-hosted customer content was exposed. | 1,59 |
| LastPass | 26-Jun-2026 · Newly retained (>24h) LastPass is the clearest named downstream example in the starter source set: it confirmed a Klue-linked customer-data incident after Klue notified it of Salesforce-related exposure. The detailed response adds Salesforce and Gong integration context, token rotation, discontinued Klue access, customer anti-phishing guidance, published IOCs, and law-enforcement cooperation. | This should be described as customer/business data exposure through a vendor integration, not a LastPass vault compromise. LastPass stated its product systems, services, infrastructure, and vault data were not compromised. | 3,4,30 |
| Huntress | Huntress publicly identified itself as an impacted organization and described the Salesforce data categories that make this operationally meaningful: business contacts, price quotes, sales communications, and competitive reports. | Use Huntress as a concrete Salesforce-object scoping pattern. Do not assume every downstream customer had the same objects, volumes, or business impact. | 7 |
| CRM data impact model | The real-world value to an attacker is not limited to one record type. Salesforce CRM exposure can include Accounts, Contacts, Leads, Opportunities, Cases, Tasks, Notes, Events, custom objects, sales strategy, pricing context, and customer-support context. | For notification and counsel review, object-level access must be proven from local Salesforce logs and customer notices, not inferred from another victim's report. | 5,6,7,25,26 |
| Jamf / Sprout Social notices | Jamf and Sprout Social notices show the downstream notification ecosystem: organizations had to review whether Klue/Salesforce access created customer, prospect, or business-data exposure in their own environments. | Each notice should be read on its own facts. A named notice is useful for scoping examples, but it is not proof that every Klue customer had the same exposure. | 11,12 |
| BeyondTrust / Snyk / HackerOne | 26-Jun-2026 · Newly retained (>24h) Newly retained downstream notices and reporting expand the public customer-disclosure set and show how organizations are scoping Salesforce business data, support-case metadata, credential/log review, and Klue disconnection. | The organizations do not report identical impacts. Use each notice on its own facts and validate with local Salesforce logs before extrapolating. | 32,33,34,35 |
| SecurityWeek expanded disclosure set | 26-Jun-2026 · Freshly reported (<24h) SecurityWeek reports roughly two dozen public Klue-Salesforce impact disclosures and names additional notice examples including AlertMedia, Camunda, Cresta, Deel, Lucanet, Link11, and Tines. | Use this as a public-disclosure count and discovery lead. Do not assign identical impact to every named organization without that organization's own notice or local Salesforce telemetry. | 36 |
| Pendo / Recorded Future / 8x8 | 26-Jun-2026 · Newly retained (>24h) Pendo and 8x8 directly disclosed Salesforce/CRM exposure through Klue with product or operational boundaries. 26-Jun-2026 · Newly retained (publication date not visible) Newly retained (publication date not visible): Recorded Future directly disclosed Salesforce impact through a Klue OAuth token while preserving its core platform, Intelligence Graph, and infrastructure boundary. | Pendo, Recorded Future, and 8x8 each define different data categories and impact limits. Their notices support scoping patterns, not a universal victim template. | 38,39,40 |
| LogicMonitor/Catchpoint / Tines / Tanium | 27-Jun-2026 · Newly retained (>24h) LogicMonitor disclosed unauthorized access to the Catchpoint Salesforce environment through Klue, while stating LogicMonitor's primary Salesforce environment and production/monitoring systems were not impacted. Tanium disclosed Salesforce CRM data exfiltration through Klue while stating Tanium products and cloud infrastructure were not impacted. 27-Jun-2026 · Newly retained (publication date not visible) Tines stated Klue credentials were used to access Salesforce data and that it found no evidence of unauthorized access to the Tines platform or customer environments. | These notices strengthen direct customer-disclosure coverage but do not create a universal impact model. Preserve each organization's Salesforce/product-system boundary. | 41,42,43 |
| OneTrust / Gong / Insurity | 28-Jun-2026 · Newly retained (>24h) OneTrust disclosed Klue Battlecards/Salesforce CRM-related data exposure and no evidence of customer-tenant exposure. Gong disclosed a Klue-originated issue for customers who connected Klue with Gong, while stating call recordings and transcripts were not directly impacted. Insurity disclosed Salesforce/Klue suspicious activity and a limited set of active credentials in exposed CRM data that it rotated or reset. 11-Jul-2026 · Newly retained (>24h) OneTrust's July 10 update says its technical investigation is complete, containment and remediation are finalized, and no exposure was found beyond its Salesforce environment. | These are first-party impact boundaries, not universal exposure statements. OneTrust's governance, compliance, and notification review remains ongoing. Treat Gong as a connected-platform disclosure rather than proof of broader Salesforce impact for every Klue customer. | 44,45,46 |
| AudienceView / Link11 / AlertMedia / Camunda / Cresta / Lucanet | 29-Jun-2026 · Freshly reported (<24h) AudienceView retained a fresh status-resolution timestamp for its Klue-Salesforce integration incident while preserving product, production-system, internal-system, and patron-data boundaries. 29-Jun-2026 · Newly retained (>24h) Link11 directly disclosed affected CRM data through its Klue OAuth-based Salesforce integration. 29-Jun-2026 · Newly retained (publication date not visible) AlertMedia, Cresta, and Lucanet add undated trust-center notices with organization-specific Salesforce or product-boundary language. 02-Jul-2026 · Newly retained (>24h) Camunda's latest update narrows its boundary to standard business-contact and account information in Salesforce CRM and says support data was not included. | Use these as additional direct disclosure examples. AudienceView's fresh label applies to the status-resolution timestamp, not to the original June 22 monitoring context; Camunda's latest label applies only to Camunda's own revised impact boundary. | 47,48,49,50,51,52 |
| ControlUp / Deel / Saviynt / ABBYY | 30-Jun-2026 · Newly retained (>24h) ControlUp, Deel, and Saviynt add direct notices for Salesforce, CRM, sales, or business-contact data exposure tied to Klue, with product and infrastructure boundaries. 30-Jun-2026 · Newly retained (publication date not visible) ABBYY adds an undated trust-center boundary for affected Salesforce data accessed through Klue's integration. | These notices expand public victimology but do not change the actor/campaign analysis, create a Salesforce platform-vulnerability finding, or establish identical data categories across customers. | 55,56,57,58 |
| Postman | 04-Jul-2026 · Newly retained (publication date not visible) Postman's Security & Trust Portal notice confirms customer contact data and sales information were exfiltrated from Salesforce via the compromised Klue service account between June 11-12. Postman says customer data was not accessed from Gong. | Preserve Postman's own boundary: the notice describes Salesforce customer contact/sales data exposure, not Gong customer-data access or a Postman core-platform compromise. | 60 |
| Automox | 05-Jul-2026 · Newly retained (>24h) Automox's Trust Center notice says Automox used Klue with Salesforce and reviewed internal logs, Salesforce Login History, Connected App OAuth usage, all API event types across the exposure period, Icarus malicious IPs, and Klue flagged egress addresses. Automox reported no anomalous or malicious activity. | Use Automox as a no-impact and leak-list deconfliction example. Automox says its data was not present in a second actor's sample and that Klue had no indication Automox data or customer data was affected. | 61 |
| eSentire | 07-Jul-2026 · Newly retained (>24h) eSentire's June 26 blog says eSentire uses Klue and was among organizations whose Salesforce data was accessed. eSentire describes the exposure as minimal because its Klue integration was tightly scoped, with restricted OAuth permissions and a limited connected-app footprint. | Preserve eSentire's own boundary: no customer-service risk was identified, and no customer communication or support interactions, threat intelligence, telemetry, credentials, passwords, or payment card data were affected. | 62 |
| Thinkproject | 08-Jul-2026 · Newly retained (>24h) Thinkproject's June 26 status notice says Klue had authorized access to Thinkproject's UAT CRM environment through a software integration and that exfiltrated data may include business-contact and commercial information. 16-Aug-2026 · Newly retained (>24h) Its Aug. 12 status resolution says the investigation has concluded, Thinkproject is not aware of misuse of the affected data, and monitoring continues. | Preserve Thinkproject's own boundary: no Thinkproject products or services were affected, and the CRM system is separate from the customer product platform. | 63 |
| Snyk / SentinelOne | 09-Jul-2026 · Newly retained (>24h) Snyk's July 8 status resolution says its Klue/Salesforce forensic investigation, conducted with Mandiant, is complete and confirmed business CRM data as the impact boundary. 09-Jul-2026 · Freshly reported (<24h) Secure ISS's July 9 advisory relays a SentinelOne partner-notification boundary: Salesforce-only impact via the Klue API integration, no lateral movement, and no core-product, cloud-infrastructure, or production impact reported. | Preserve both boundaries separately: Snyk closes on business CRM data with no platform impact; SentinelOne is retained as a qualified public advisory/partner-notification lead because the direct portal reference is access-controlled and data analysis remains ongoing. | 64,65 |
| Follow-on extortion pressure | 26-Jun-2026 · Freshly reported (<24h) TechCrunch reports Klue told customers that the original criminals were deleting stolen data while a second group had begun making threats. | Treat second-wave contact as an extortion and evidence-preservation lead. Do not assume possession, completeness, or authenticity without source/customer-specific proof. | 31 |
| Microsoft ShinyHunters-associated OAuth abuse research | 13-Jul-2026 · Freshly reported (<24h) Microsoft groups Salesforce and SaaS OAuth-abuse campaigns observed from mid-2025 to mid-2026 as tradecraft commonly associated with ShinyHunters, and includes Klue integration Salesforce API activity as part of that broader defensive context. 18-Jul-2026 · Newly retained (>24h) Microsoft also names Storm-3138 for the Klue system-access path. | Use this as tradecraft, activity-label, and detection enrichment. It does not add a named public victim row and should not override the Klue-specific Icarus/ICARUS extortion/operator boundary without direct corroboration. | 66 |
| Sisense | 14-Jul-2026 · Newly retained (publication date not visible) Sisense's Trust Center says Sisense was one of many affected organizations and that the incident was limited to certain business and sales-related data in its Salesforce CRM application. | Preserve Sisense's own boundary: it states the Sisense product platform and data stored within the product platform were not impacted, and the notice has no visible publication date. | 67 |
| Qualtrics / Splashtop | 16-Jul-2026 · Newly retained (>24h) Qualtrics says the Klue application connected to Salesforce to support internal sales teams, unauthorized access was limited to a subset of Salesforce data, and impacted data included business-to-business identifiers. Splashtop says Klue OAuth tokens were used to access certain Salesforce data and that it disabled the Klue Salesforce integration and revoked associated access. | Preserve each organization's own boundary: Qualtrics excludes products, core infrastructure, services, and hosted platform customer data; Splashtop excludes product and service impact while noting its investigation remained ongoing. | 68,69 |
| Greenhouse / Blackbaud | 23-Jul-2026 · Newly retained (>24h) Greenhouse's trust-center notice says attackers obtained Klue credentials used to connect to certain Greenhouse business systems, access occurred on June 11, was scoped to Klue's integration, and accessible data was limited to business contact information in sales/customer relationship systems. Blackbaud's July 22 update says its investigation remains ongoing with no substantive update and no known Blackbaud product or business-operations impact. | Preserve both organizations' own boundaries: Greenhouse excludes Greenhouse product, hiring, candidate, infrastructure, modification, and deletion impact; Blackbaud does not publish data-category detail in the public page and directs active customers to logged-in FAQ/update material. | 70,71 |
| Confluent | 24-Jul-2026 · Newly retained (publication date not visible) Confluent's public trust-center statement says Klue was used by its sales and marketing teams, and that copied data was limited to Confluent business information stored in its CRM system, such as business-contact and go-to-market opportunity information. | Preserve Confluent's stated boundary: data processed through Confluent products was not involved or impacted, and there is no indication Confluent products, platform, or infrastructure were affected. | 72 |
| Autodesk | 28-Jul-2026 · Newly retained (>24h) Autodesk's trust-center advisory says Klue notified Autodesk on June 16 and that Autodesk confirmed it does not use the Salesforce or Gong integrations for Klue. | Preserve Autodesk's stated boundary: no direct impact to Autodesk products or services and no impact to Autodesk systems. | 73 |
| Yext | 02-Aug-2026 · Newly retained; undated Yext's SafeBase trust-center notice says stolen Klue-held credentials were used to run read-only queries against Yext's internal Salesforce CRM for roughly 17 hours on June 11-12, exposing business contact details for customers and prospects. | Preserve Yext's own boundary: no data was created, changed, or deleted, and Yext excludes platform, product, infrastructure, customer-content, customer-facing-system, end-user-data, payment-card, Google Workspace, and Slack impact. The notice has no visible publication date. | 76 |
| Commvault / NetDocuments | 03-Aug-2026 · Newly retained (>24h) Commvault's rendered Vanta trust-center notice says accessed data was limited to business relationship and sales activity information in its Salesforce environment. NetDocuments' rendered TrustShare advisory says Klue-related impact was limited to a list of internal staff who are Gong users. | Preserve both organizations' own boundaries: Commvault excludes customer data, Commvault solutions/services, customer backup data, product metadata, and logs; NetDocuments excludes the NetDocuments Service, customer data, prospective customer data, and Customer Repository Data. | 77,78 |
| Neon One | 04-Aug-2026 · Newly retained (>24h) Neon One's July 31 notice letter says Klue provided an integration service for Neon One's Salesforce customer relationship management software, and that the Klue incident resulted in unauthorized access to some personal information between June 11 and June 12. | Preserve Neon One's own boundary: the notice says the incident was contained and no further impact was identified, but the public sample letter does not publish the specific personal-information elements. | 79 |
| Betterment | 10-Aug-2026 · Newly retained (>24h) Betterment's August 5 notice letter hosted by the Massachusetts Attorney General data-breach portal says Klue Labs Inc. was a vendor used by Betterment's sales team and had access to a Salesforce database containing Betterment data.11-Aug-2026 · Newly retained (>24h) PDF text re-review adds that unauthorized access involved a file containing name and Social Security number, that Betterment's computer systems were not accessed, and that two years of Kroll identity monitoring were offered. | Preserve Betterment's own boundary: treat this as a Klue/Salesforce notice-letter disclosure involving the public name/SSN file language, but do not infer Betterment product-system, brokerage, bank, account-access, or credential compromise from the notice text. | 80 |
| Investigation takeaway | The practical lesson is that a trusted SaaS integration can create a downstream Salesforce breach path even when the downstream customer's own product systems were not initially compromised. | Scope the connected app, OAuth tokens, API activity, and exact CRM objects before writing executive, legal, or customer-notification language. | 1,3,5,6,7 |
23-Public Victims / Disclosure Matrix
Public Klue-related customer notices should be read as organization-specific Salesforce or CRM exposure statements. Do not turn one notice into a universal impact model; each row below preserves who disclosed the impact and the boundary that source stated.
| Victim / Organization | Confirmed? | Reported / Disclosed By | Impact Boundary |
|---|---|---|---|
| LastPass | Confirmed public customer statement | LastPass statement and BleepingComputer reporting 3,4,30 | Customer/business-data issue tied to Klue/Salesforce context; LastPass stated product systems, services, infrastructure, and vault data were not compromised. |
| Huntress | Confirmed public customer statement | Huntress disclosure 7 | Salesforce data categories were described publicly; use as an object-scoping example, not a universal exposure template. |
| Jamf / Sprout Social | Confirmed public notices | Customer trust-center notices 11,12 | Downstream notification examples showing customer/prospect/business-data review; each notice stands on its own facts. |
| BeyondTrust / Snyk / HackerOne | Publicly reported or noticed | Customer notices and reporting 32,33,34,35 | Useful for disclosure-pattern analysis; reported impacts and product-system boundaries differ by organization. |
| Pendo / Recorded Future / 8x8 | Confirmed public notices | Customer disclosures 38,39,40 | Salesforce/CRM exposure language is source-specific; several notices preserve explicit core-product or platform boundaries. |
| LogicMonitor/Catchpoint / Tines / Tanium | Confirmed public notices | Customer disclosures 41,42,43 | Each notice separates Salesforce or Klue-connected exposure from production, platform, or customer-environment boundaries. |
| OneTrust / Gong / Insurity | Confirmed public notices | 28-Jun-2026 · Newly retained (>24h) Customer and connected-platform disclosures 44,45,46 11-Jul-2026 · Newly retained (>24h) OneTrust investigation-complete update 44 | OneTrust now states its technical investigation, containment, and remediation are complete and that the independent forensic investigation found no evidence of exposure beyond OneTrust's Salesforce environment; Gong limits direct impact away from call recordings and transcripts; Insurity limits product impact and says a small credential set was rotated or reset. |
| AudienceView / Link11 / AlertMedia / Camunda / Cresta / Lucanet | Confirmed public notices | 29-Jun-2026 · Freshly reported (<24h) AudienceView status notice 47 29-Jun-2026 · Newly retained (>24h) Link11 disclosure 48 29-Jun-2026 · Newly retained (publication date not visible) AlertMedia, Cresta, and Lucanet trust-center notices 49,51,52 02-Jul-2026 · Newly retained (>24h) Camunda boundary revision 50 | AudienceView separates Klue-Salesforce integration impact from product, production, internal-system, and patron-data compromise; Link11 describes certain CRM data affected; Camunda now excludes support data and limits its disclosure to standard business-contact and account information in Salesforce CRM; AlertMedia, Cresta, and Lucanet each require their own trust-center boundary. |
| ControlUp / Deel / Saviynt / ABBYY | Confirmed public notices | 30-Jun-2026 · Newly retained (>24h) ControlUp, Deel, and Saviynt notices 55,56,57 30-Jun-2026 · Newly retained (publication date not visible) ABBYY Trust Center notice 58 | ControlUp, Deel, and Saviynt separate Salesforce/CRM or sales-data exposure from product, production, infrastructure, service, or product-customer-data compromise; ABBYY states its network, products, and technology were not affected. |
| Postman | Confirmed public notice | 04-Jul-2026 · Newly retained (publication date not visible) Postman Security & Trust Portal notice 60 | Postman confirms Salesforce customer contact and sales information exfiltration via Klue, excludes customer data access from Gong, and states core platform services remain secure and were not impacted. |
| Automox | Public no-impact notice | 05-Jul-2026 · Newly retained (>24h) Automox Trust Center notice 61 | Automox reports Klue/Salesforce exposure review, no anomalous or malicious Salesforce activity, no Automox data in a second actor sample, and Klue confirmation that it had no indication Automox data or customer data was affected. |
| eSentire | Confirmed public notice | 07-Jul-2026 · Newly retained (>24h) eSentire blog 62 | eSentire reports minimal Salesforce exposure due to restricted OAuth permissions and a limited connected-app footprint, no identified customer-service risk, and no affected customer communications, support interactions, threat intelligence, telemetry, credentials, passwords, or payment-card data. |
| Thinkproject | Confirmed public status notice | 08-Jul-2026 · Newly retained (>24h) Thinkproject status notice 63 16-Aug-2026 · Newly retained (>24h) Aug. 12 status resolution 63 | Thinkproject reports Salesforce/Klue access to a UAT CRM environment, possible business-contact and commercial-information exposure, no product or service impact, CRM separation from the customer product platform, investigation closure, no known misuse of affected data, and continued monitoring. |
| Snyk / SentinelOne | Snyk confirmed status resolution; SentinelOne qualified public advisory | 09-Jul-2026 · Newly retained (>24h) Snyk status resolution 64 09-Jul-2026 · Freshly reported (<24h) Secure ISS advisory relaying SentinelOne partner-notification details 65 | Snyk reports a completed Mandiant-assisted investigation, business CRM data only, and no Snyk platform or sensitive platform-data impact. Secure ISS reports SentinelOne impact contained to Salesforce via Klue API integration, with no lateral movement or core-product/cloud/production impact; SentinelOne data analysis remains ongoing. |
| Sisense | Confirmed public trust-center notice | 14-Jul-2026 · Newly retained (publication date not visible) Sisense Trust Center notice 67 | Sisense reports impact limited to certain business and sales-related data stored in its Salesforce CRM application, with no impact to the Sisense product platform or product-platform data. The trust-center notice has no visible publication date. |
| Qualtrics / Splashtop | Confirmed public notices | 16-Jul-2026 · Newly retained (>24h) Qualtrics and Splashtop direct notices 68,69 | Qualtrics reports unauthorized access to a subset of Salesforce data, including business-to-business identifiers, while excluding products, core infrastructure, services, and hosted platform customer data. Splashtop reports certain Salesforce data access through Klue OAuth tokens, disabled/revoked Klue Salesforce access, no product or service impact, and an ongoing investigation. |
| Greenhouse / Blackbaud | Confirmed public trust-center notices | 23-Jul-2026 · Newly retained (>24h) Greenhouse and Blackbaud Conveyor trust-center notices 70,71 | Greenhouse reports access scoped to Klue's integration, business-contact data in sales/customer relationship systems, no Greenhouse product, hiring, candidate, infrastructure, modification, or deletion impact, and data-protection authority notification. Blackbaud reports an ongoing investigation with no substantive update, no known Blackbaud product impact, and no business-operations or customer-service impact. |
| Confluent | Confirmed public trust-center notice | 24-Jul-2026 · Newly retained (publication date not visible) Confluent SafeBase trust-center statement 72 | Confluent limits copied data to business information stored in its CRM system, including business-contact and go-to-market opportunity information, and excludes product-processed customer data, products, platform, and infrastructure impact. |
| Autodesk | Public no-impact trust-center advisory | 28-Jul-2026 · Newly retained (>24h) Autodesk Trust Center advisory 73 | Autodesk says Klue notified it on June 16, Autodesk did not use the Salesforce or Gong integrations for Klue, and Autodesk identified no direct impact to Autodesk products, services, or systems. |
| Yext | Confirmed public trust-center notice | 02-Aug-2026 · Newly retained; undated Yext SafeBase trust-center notice 76 | Yext reports read-only Salesforce CRM queries for roughly 17 hours on June 11-12 through stolen Klue-held credentials, exposed customer/prospect business contact details, no create/change/delete activity, and no Yext platform, product, infrastructure, customer-content, customer-facing-system, end-user-data, payment-card, Google Workspace, or Slack impact. |
| Commvault / NetDocuments | Confirmed public trust-center/customer-advisory notices | 03-Aug-2026 · Newly retained (>24h) Commvault Trust Center and NetDocuments TrustShare notices 77,78 | Commvault reports Salesforce business relationship and sales activity information access, including business contact information, internal account information, sales opportunities, and partner status, while excluding customer data, Commvault solutions/services, customer backup data, product metadata, and logs. NetDocuments reports impact limited to internal Gong-user staff-list data and excludes customer data, prospective customer data, Customer Repository Data, and NetDocuments Service impact. |
| Neon One | Confirmed public notice letter | 04-Aug-2026 · Newly retained (>24h) Neon One Notice of Data Breach 79 | Neon One reports a Klue incident involving an integration service for Neon One's Salesforce CRM software, unauthorized access to some personal information between June 11-12, containment, and no further identified impact. The public sample notice does not disclose the specific personal-information elements. |
| Betterment | Confirmed public notice letter | 10-Aug-2026 · Newly retained (>24h) Betterment notice letter hosted by Mass.gov 80 | Mass.gov indexed the August 5 Betterment PDF as a data-breach notice; PDF text re-review says Klue Labs Inc. was a vendor used by Betterment's sales team with access to a Salesforce database containing Betterment data, unauthorized access involved a file containing name and Social Security number, Betterment's computer systems were not accessed, and two years of Kroll identity monitoring were offered. Do not expand this into Betterment product, brokerage, bank, account-access, credential, or raw stolen-data claims. |
| Additional named public disclosure leads | Reported, verify per organization | SecurityWeek expanded disclosure reporting 36 | Use as discovery leads for public notices; do not treat every named organization as having identical data categories or impact. |
24-KEV and CVE Details
No CISA KEV or CVE entry is associated with the Klue incident in this source set. This is a supply-chain, token, and SaaS integration trust issue; response should not wait for CVE/KEV framing.
25-MITRE ATT&CK Lifecycle Mapping
| MITRE Tactic / Phase | Technique | Klue Incident Mapping | Defender Breakpoint | Sources |
|---|---|---|---|---|
| Initial Access | T1199: Trusted Relationship | 02-Jul-2026 · Freshly reported (<24h) Klue's CrowdStrike summary says a previously compromised GitHub PAT enabled unauthorized code in the integration service that collected third-party credentials, including Salesforce OAuth tokens. | Validate third-party connected apps, service accounts, token state, vendor source-control controls, integration-service runtime containment, and Klue reauthorization boundaries. | 1,5,14,59 |
| Credential Access | T1528: Steal Application Access Token | The useful access material is the Salesforce OAuth access/refresh-token relationship, not a normal user password reset problem. | Review OAuth usage, token revocation evidence, authorized users, app scopes, connected-app policy, and vendor evidence that OAuth credentials were rotated. | 1,5,6,15,59 |
| Persistence | T1671: Cloud Application Integration | 13-Jul-2026 · Freshly reported (<24h) Microsoft maps Salesforce OAuth abuse to connected-app integration leverage, reinforcing that trusted SaaS grants can become durable access paths. | Inventory authorized apps, review OAuth consent and app privileges, validate connected-app attribution, and alert on CRM querying from unexpected app or source contexts. | 66 |
| Defense Evasion | T1078: Valid Accounts | Token-backed app activity can look like authorized Salesforce integration use until EventLogFile and connected-app telemetry are reviewed. | Correlate connected-app identity, source IP, user agent, REST API events, Login History, and Setup Audit Trail. | 5,6,16,25,26,27,28 |
| Collection | T1119: Automated Collection | Researchers describe automated Salesforce REST API queries and object-level access patterns that require tenant-specific validation. | Review REST API, query/queryMore, API usage, report/report export, and object-specific access against Accounts, Contacts, Leads, Opportunities, Cases, Tasks, Notes, and custom objects. | 5,6,25,26,29 |
| Exfiltration | T1567.002: Exfiltration to Cloud Storage | Public reporting supports data access and exfiltration risk from connected Salesforce environments, but exact objects and counts vary by customer. | Scope exposed CRM records per tenant before notification conclusions. | 5,6,7,17 |
26-Source Weighting / Relevance
| Source Group | Contribution | Confidence | Caveat |
|---|---|---|---|
| Primary statements | 02-Jul-2026 · Freshly reported (<24h) Klue/CrowdStrike adds primary mechanism and containment detail: GitHub PAT (personal access token), unauthorized integration-service code, Salesforce OAuth token collection, GKE pod containment, no identified access outside integration-service-related systems, no activity after June 12, and hardening actions. 02-Jul-2026 · Newly retained (>24h) Camunda narrows its own customer-notice boundary to standard business-contact and account information. 04-Jul-2026 · Newly retained (publication date not visible) Several trust-center notices, including Postman's direct Salesforce/Gong boundary, remain undated and should not be treated as fresh. 05-Jul-2026 · Newly retained (>24h) Automox adds a dated no-impact notice that is high value for source deconfliction, not victim expansion. 07-Jul-2026 · Newly retained (>24h) eSentire adds a dated direct minimal-exposure disclosure and customer-service boundary. 08-Jul-2026 · Newly retained (>24h) Thinkproject adds a dated UAT CRM customer-disclosure boundary. 16-Aug-2026 · Newly retained (>24h) Thinkproject adds a dated investigation-closure/no-known-misuse update for the same UAT CRM boundary. 11-Jul-2026 · Newly retained (>24h) OneTrust adds a dated investigation-complete update with no exposure found beyond Salesforce. 14-Jul-2026 · Newly retained (publication date not visible) Sisense adds an undated direct trust-center disclosure for Salesforce CRM business/sales data and product-platform exclusion. 16-Jul-2026 · Newly retained (>24h) Qualtrics and Splashtop add older direct public customer-disclosure boundaries for Salesforce data access, product/platform exclusions, and Splashtop's ongoing-investigation caveat. 23-Jul-2026 · Newly retained (>24h) Greenhouse and Blackbaud add direct trust-center boundaries; Greenhouse publishes business-contact data and product/hiring/candidate/infrastructure exclusions, while Blackbaud publishes an ongoing-investigation/no-known-product-or-business-operations-impact update. 24-Jul-2026 · Newly retained (publication date not visible) Confluent adds an undated direct trust-center boundary for CRM business information with product-processed-customer-data and platform exclusions. 02-Aug-2026 · Newly retained; undated Yext adds an undated direct SafeBase boundary for read-only internal Salesforce CRM queries, exposed customer/prospect business-contact details, no create/change/delete activity, and platform/product/infrastructure/customer-content/customer-facing/end-user/payment-card/Google Workspace/Slack exclusions. 03-Aug-2026 · Newly retained (>24h) Commvault and NetDocuments add older rendered direct disclosure boundaries for Salesforce business relationship/sales activity data and internal Gong-user staff-list data, with customer-data, product/service, backup, metadata, log, Customer Repository Data, and service-impact exclusions. 04-Aug-2026 · Newly retained (>24h) Neon One adds an older direct notice-letter boundary for Klue-linked Salesforce CRM integration access to some personal information, while not publishing the specific elements in the sample notice. 10-Aug-2026 · Newly retained (>24h) Betterment adds an older Mass.gov-hosted notice-letter boundary for Klue Labs sales-team vendor access to a Salesforce database containing Betterment data. 11-Aug-2026 · Newly retained (>24h) Betterment PDF text re-review adds public name/SSN, no-Betterment-computer-system-access, and two-year Kroll identity-monitoring boundaries. | High for source existence; medium for detailed impact scope | Not every detail of object-level exposure is public; no-impact, minimal-impact, UAT-specific, investigation-complete, ongoing-investigation, no-known-impact, and undated, rendered trust-center, indexed PDF, or sample notice-letter disclosures should not be rewritten as universal outcomes for other customers. |
| Technical research | 13-Jul-2026 · Freshly reported (<24h) Microsoft adds ShinyHunters-associated SaaS OAuth-abuse tradecraft context, connected-app integration mapping, and Klue IOC enrichment. 18-Jul-2026 · Newly retained (>24h) Microsoft's Storm-3138 label is now retained as a Klue system-access activity label. ReliaQuest, Datadog, Huntress, Obsidian, and ZeroFox provide Klue-specific hunting and attack-flow detail. | Medium-High | Confirm exact indicators and objects locally. Do not treat Storm-3138 or shared OAuth-abuse tradecraft as definitive proof of a merged actor/campaign across Klue, Icarus/ICARUS, UNC6395, Salesloft Drift, Gainsight, and ShinyHunters. |
| Security media | BleepingComputer, TechCrunch, SecurityWeek, and trade press make the story visible, connect named downstream organizations, and flag follow-on extortion posture. | Medium | Do not let media summaries override primary notices. |
| MITRE / Salesforce docs | Framework and platform documentation explain why trusted apps, tokens, and connected apps are the right control layer. | High for definitions | Definitions do not prove impact. |
27-Additional IntelliOS Threat Intel Products on This Topic
Icarus Threat Actor Snapshot
Use the full intelligence product for Icarus attribution boundaries, OAuth-abuse tradecraft, victimology, response priorities, and the cumulative AI Agent assessment.
Icarus Actor Card
Open the canonical CARDS identity record for aliases, linked activity, source reconciliation, briefing points, and related campaigns.
Klue Salesforce OAuth Supply-Chain Attack
Open the canonical campaign card for the Klue incident, associated actors, OAuth mechanics, affected scope, defensive takeaways, and retained source boundaries.
Salesloft Drift OAuth Supply-Chain Attack
Use this as the closest Salesforce SaaS/OAuth supply-chain comparator: trusted integration tokens, downstream Salesforce exposure, token revocation, and CRM-object scoping.
28-Notes
Create an account and sign-in to use this card.
Record your personal notes and comments in this card related to this brief.
29-Version Change Log
| Version | Date | Changes |
|---|---|---|
| v1.0 | June 23, 2026 | Initial static Klue Flash Threat Intel Brief covering Klue, LastPass downstream impact, Salesforce OAuth/token framing, and Salesloft Drift expansion research. |
| v1.1 | June 24, 2026 | Added deeper battlecard and competitive-enablement definitions, Salesforce forensic logging guidance, MITRE lifecycle remap, quoted talking points, Salesloft reciprocal link, and versioned change log. |
| v1.2 | June 26, 2026 | Created the Klue AI Monitoring Agent, added dated delta badge/legend support, and incorporated bootstrap monitor deltas: TechCrunch follow-on extortion reporting (Freshly reported (<24h)), plus newly retained LastPass, SecurityWeek, Snyk, HackerOne, and BeyondTrust sources (Newly retained (>24h)). Updated executive summary, AI Agent Delta Updates, timeline, IOCs/observables, source coverage, source summary, source deconfliction, real-world examples, citations, and PANDA index dates. |
| v1.3 | June 26, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated source-backed deltas: SecurityWeek's 26-Jun-2026 11:01 AM ET follow-up (Freshly reported (<24h)) expanded the public disclosure set to roughly two dozen customer notices; Obsidian, Pendo, and 8x8 were newly retained (Newly retained (>24h)); Recorded Future was Newly retained (publication date not visible). Added Salesforce forensic refinements for Global Describe, QueryMore, API-version/user-agent deviation, additional public-victim examples, and Icarus/UNC6395 deconfliction. No reliable source merged Klue with UNC6395/Salesloft Drift. |
| v1.4 | June 27, 2026, 9:33 PM ET | AI Monitoring Agent found and incorporated source-backed direct customer-disclosure deltas. Added LogicMonitor/Catchpoint and Tanium as Newly retained (>24h), added Tines Trust Center as Newly retained (publication date not visible), and updated Executive Summary, AI Agent Delta Updates, Timeline, Real World Examples, Source Summary, Source Deconfliction, Citations, and related PANDA index entries. Public victim/disclosure search found additional direct customer notices. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. No Freshly reported (<24h) source was retained. |
| v1.5 | June 28, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated source-backed direct customer and connected-platform disclosure deltas. Added OneTrust, Gong, and Insurity as Newly retained (>24h), with retrieval timestamp 28-Jun-2026 9:31 PM ET. Updated Executive Summary, AI Agent Delta Updates, Timeline, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Citations, related PANDA index entries, and the AI Monitoring Agent directory. Public victim/disclosure search found additional direct notices. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. No Freshly reported (<24h) source was retained. |
| v1.6 | June 29, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated source-backed direct customer-disclosure, sector-guidance, and actor-context deltas. Freshly reported (<24h): AudienceView status-page resolution timestamp, with older initial monitoring context preserved. Newly retained (>24h): Link11, FINRA, and ZeroFox. Newly retained (publication date not visible): AlertMedia, Camunda, Cresta, and Lucanet trust-center notices. Updated Executive Summary, AI Agent Delta Updates, Timeline, Incident Response Playbook Ideas, Salesforce forensics guidance, IOCs/Observables, Threat Actor Glossary, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Citations, and related PANDA index entries. Public victim/disclosure search found additional direct notices. Associated-campaign/activity-cluster search reinforced Icarus/ICARUS and Underground Uwu/SLH caveats; no reliable source merged Klue with UNC6395/Salesloft Drift. |
| v1.7 | June 30, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated source-backed direct customer-disclosure deltas. Newly retained (>24h): ControlUp, Deel, and Saviynt. Newly retained (publication date not visible): ABBYY Trust Center. Updated Executive Summary, AI Agent Delta Updates, Timeline, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Citations, and related PANDA index entries. Public victim/disclosure search found additional direct notices. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. No Freshly reported (<24h) source was retained. |
| v1.7 | July 1, 2026, 9:31 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, secondary rewrites, previously retained direct notices, leak-site-only claims, aggregator pages, LinkedIn/social posts, and unsupported UNC6395/Salesloft Drift conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 1, 2026. |
| v1.8 | July 2, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated source-backed primary mechanism, containment, and customer-boundary deltas. Freshly reported (<24h): Klue CrowdStrike Investigation Summary and Security Improvements, schema published 02-Jul-2026 12:02 AM ET with a visible 01-Jul-2026 byline, adding the compromised GitHub PAT, unauthorized integration-service code, Salesforce OAuth access/refresh token collection, affected GKE pod containment, no identified access outside integration-service-related systems, no activity after June 12, CrowdStrike Falcon monitoring, and CI/CD/security hardening. Newly retained (>24h): Camunda Trust Center 01-Jul-2026 6:00 PM ET update narrowing Camunda's support-data boundary to standard business-contact and account information in Salesforce CRM. Updated Executive Summary, BLUF, Timeline, Incident Response Playbook Ideas, Salesforce forensics guidance, MITRE ATT&CK mapping, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, and related PANDA index entries. Public-victim/disclosure search found a Camunda boundary revision but no new named public victim row. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. |
| v1.9 | July 4, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated a source-backed direct customer-disclosure delta. Newly retained (publication date not visible): Postman Security & Trust Portal Notice of Security Incident, retrieved 04-Jul-2026 9:31 PM ET, confirming Salesforce customer contact and sales-information exfiltration via the compromised Klue service account between June 11-12, while stating customer data was not accessed from Gong and Postman's core platform services remained secure and were not impacted. Updated Executive Summary, BLUF, Timeline, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, related PANDA index entries, and the AI Monitoring Agent directory. Public-victim/disclosure search found Postman's direct notice. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. No Freshly reported (<24h) source was retained. PANDA index date updated to Updated Jul 4, 2026. |
| v1.10 | July 5, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated a source-backed no-impact/deconfliction delta. Newly retained (>24h): Automox Trust Center Klue Security Incident, published 29-Jun-2026 and retrieved 05-Jul-2026 9:31 PM ET, stating Automox used Klue with Salesforce, reviewed internal logs and Salesforce Login History/Connected App OAuth usage, found no anomalous or malicious Salesforce activity, and said Klue had no indication Automox data or customer data was affected. Updated BLUF, Timeline, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, and related PANDA index entries. Public-victim/disclosure search found Automox's direct no-impact notice and rejected NetDocuments search-index-only text, duplicative SEO rewrites, social posts, leak-site-only claims, and unsupported speculation. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained. PANDA index date updated to Updated Jul 5, 2026. |
| v1.10 | July 6, 2026, 9:31 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, secondary rewrites, previously retained direct notices, leak-site-only claims, social posts, source-index/status aggregators, and unsupported UNC6395/Salesloft Drift conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 6, 2026. |
| v1.11 | July 7, 2026, 9:32 PM ET | AI Monitoring Agent found and incorporated a source-backed direct customer-disclosure delta. Newly retained (>24h): eSentire Responding to the Klue Incident, published 26-Jun-2026 and retrieved 07-Jul-2026 9:32 PM ET, stating eSentire uses Klue, was among organizations whose Salesforce data was accessed, characterized exposure as minimal due to restricted OAuth permissions and a limited connected-app footprint, identified no customer-service risk, and excluded customer communications, support interactions, threat intelligence, telemetry, credentials, passwords, and payment-card data. Updated BLUF, Timeline, Executive Summary, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, related PANDA index entries, and the AI Monitoring Agent directory. Public-victim/disclosure search found eSentire's direct notice and rejected NetDocuments sparse/search-index-only text, generic OAuth/Salesforce recaps, social posts, leak-site-only claims, and duplicate media rewrites. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained. PANDA index date remained Updated Jul 7, 2026. |
| v1.12 | July 8, 2026, 9:32 PM ET | AI Monitoring Agent found and incorporated a source-backed direct customer-disclosure delta. Newly retained (>24h): Thinkproject Status Klue Breach that Allowed Data Exfiltration from Salesforce, published 26-Jun-2026 6:47 AM and retrieved 08-Jul-2026 9:32 PM ET, stating Klue had authorized access to Thinkproject's UAT CRM environment through a software integration, exfiltrated data may include business-contact and commercial information, Thinkproject products and services were not affected, and the CRM system is separate from the customer product platform. Updated BLUF, Timeline, Executive Summary, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, and related PANDA index entries. Public-victim/disclosure search found Thinkproject's direct notice and rejected duplicative summaries, generic Salesforce OAuth recaps, social posts, leak-site-only claims, sparse status aggregators, and duplicate media rewrites. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained. PANDA index date updated to Updated Jul 8, 2026. |
| v1.13 | July 9, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated source-backed customer-boundary deltas. Newly retained (>24h): Snyk Status Third-Party Vendor Security Incident (Klue), resolved 08-Jul-2026 11:26 AM ET and retrieved 09-Jul-2026 9:31 PM ET, stating Snyk's Mandiant-assisted Klue/Salesforce forensic investigation is complete, impact was limited to business CRM data, and no Snyk platform or sensitive platform-data impact was found. Freshly reported (<24h): Secure ISS SentinelOne Klue advisory, published 09-Jul-2026 and retrieved 09-Jul-2026 9:31 PM ET, relaying a SentinelOne partner-notification boundary that impact was contained to Salesforce through the Klue API integration, with no lateral movement and no core-product, cloud-infrastructure, or production-environment impact reported; data analysis remains ongoing and the direct SentinelOne portal reference is access-controlled. Updated BLUF, Timeline, Executive Summary, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, related PANDA index entries, and the AI Monitoring Agent directory. Public-victim/disclosure search found Snyk's status resolution and a qualified SentinelOne public advisory/partner-notification lead; NetDocuments JavaScript-only/search-index text, duplicative SEO recaps, generic OAuth commentary, leak-site-only claims, and unsupported Salesforce/OAuth attribution rewrites were not promoted. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. No Newly retained (publication date not visible) source was retained. PANDA index date updated to Updated Jul 9, 2026. |
| v1.13 | July 10, 2026, 9:32 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, secondary rewrites, generic Salesforce/OAuth commentary, leak-site-only claims, social posts, access-controlled portal references, JavaScript-only trust-center app shells, and unsupported UNC6395/Salesloft Drift conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief. NetDocuments remained JavaScript-only/search-index text without a stable inspectable disclosure body. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 10, 2026. |
| v1.14 | July 11, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated a source-backed customer-boundary delta. Newly retained (>24h): OneTrust Update From OneTrust on Klue Security Incident, updated 10-Jul-2026 and retrieved 11-Jul-2026 9:31 PM ET, stating OneTrust's technical investigation, scope validation, containment, and remediation are complete and that the independent forensic investigation found no evidence of exposure beyond OneTrust's Salesforce environment while governance, compliance, and notification review continue. Updated BLUF, Timeline, Executive Summary, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, Contributors, and related PANDA index review status. Public-victim/disclosure search found OneTrust's direct investigation-complete update and rejected duplicate media recaps, social posts, leak-site-only claims, generic OAuth/Salesforce commentary, and unsupported Klue/Salesloft Drift conflation. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained. PANDA index date remained Updated Jul 11, 2026. |
| v1.14 | July 12, 2026, 9:31 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, secondary rewrites, generic Salesforce/OAuth commentary, leak-site-only claims, social posts, access-controlled portal references, JavaScript-only trust-center app shells, and unsupported Icarus/UNC6395/Salesloft Drift conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 12, 2026. |
| v1.15 | July 13, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated a source-backed campaign/activity-cluster deconfliction delta. Freshly reported (<24h): Microsoft Security Research / Microsoft Defender Security Research Team, published 13-Jul-2026 and retrieved 13-Jul-2026 9:31 PM ET, placing Klue-related Salesforce/SaaS OAuth abuse inside broader ShinyHunters-associated tradecraft context, adding connected-app visibility guidance, MITRE T1671 mapping, and Microsoft Klue IOC enrichment. Updated BLUF, Executive Summary, Timeline, AI Agent Delta Updates, Incident Response Playbook Ideas, Salesforce forensics guidance, IOCs/Observables, Threat Actor Glossary, Talking Points, Decision Ready Actions, Real World Examples, MITRE ATT&CK Lifecycle Mapping, Source Summary, Source Deconfliction, Source Weighting, Citations, and related PANDA index entries. Public-victim/disclosure search found no new reliable named public organization notice requiring a victim/disclosure row. Associated-campaign/activity-cluster search found Microsoft ShinyHunters-associated OAuth-abuse research that improves deconfliction but does not merge Klue/Icarus with UNC6395 or Salesloft Drift. Freshness labels applied to retained sources: Freshly reported (<24h). PANDA index date updated to Updated Jul 13, 2026. |
| v1.16 | July 14, 2026, 9:32 PM ET | AI Monitoring Agent found and incorporated a source-backed direct customer-disclosure delta. Newly retained (publication date not visible): Sisense Trust Center Security Update: Klue Security Incident, retrieved 14-Jul-2026 9:32 PM ET, stating Sisense was one of many affected organizations, limiting impact to certain business and sales-related data in Sisense's Salesforce CRM application, excluding Sisense product-platform and product-platform data impact, and noting credential/token rotation and access-log monitoring. Updated BLUF, Executive Summary, Timeline, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, and related PANDA index entries. Public-victim/disclosure search found Sisense's direct trust-center notice and rejected duplicate media recaps, SEO rewrites, leak-site-only claims, JavaScript-only NetDocuments text, generic Salesforce/OAuth commentary, and unsupported Klue/Salesloft Drift conflation. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. No Freshly reported (<24h) or Newly retained (>24h) source was retained. PANDA index date updated to Updated Jul 14, 2026. |
| v1.16 | July 15, 2026, 9:31 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, secondary rewrites, generic Salesforce/OAuth commentary, leak-site-only claims, JavaScript-only trust-center app shells, unavailable trust-center bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. Microsoft ShinyHunters OAuth coverage remained represented by the existing Microsoft source and did not create a new delta. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 15, 2026. |
| v1.17 | July 16, 2026, 9:32 PM ET | AI Monitoring Agent found and incorporated source-backed direct customer-disclosure deltas. Newly retained (>24h): Qualtrics XM Trust Center Klue Supply Chain Compromise response, published 25-Jun-2026 12:55 UTC and retrieved 16-Jul-2026 9:32 PM ET, stating Klue connected to Salesforce for internal sales-team support, unauthorized access was limited to a subset of Salesforce data, impacted data included business-to-business identifiers, and Qualtrics products, core infrastructure, services, and hosted platform customer data were not accessed or compromised; Splashtop Security Update Regarding Third-Party Klue Incident, updated 30-Jun-2026 and retrieved 16-Jul-2026 9:32 PM ET, stating Klue OAuth tokens were used to access certain Salesforce data, Splashtop disabled the Klue Salesforce integration and revoked access, Splashtop products/services were not impacted, and investigation remained ongoing. Updated BLUF, Executive Summary, Timeline, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, Contributors, and related PANDA index entries. Public-victim/disclosure search found Qualtrics and Splashtop direct notices and rejected duplicate media recaps, VenariX aggregated victim tracking, NetDocuments and Commvault JavaScript-only trust-center shells without stable inspectable bodies, leak-site-only claims, generic Salesforce/OAuth commentary, and unsupported Klue/Salesloft Drift conflation. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained. Freshness labels applied to retained sources: Newly retained (>24h). PANDA index date updated to Updated Jul 16, 2026. |
| v1.18 | July 18, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated a source-backed campaign/activity-label clarification from the already retained Microsoft Security Research / Microsoft Defender Security Research Team July 13 source. Newly retained (>24h): Microsoft's Storm-3138 label for the Klue system-access path, re-reviewed 18-Jul-2026 9:31 PM ET. Updated BLUF, Executive Summary, Timeline, AI Agent Delta Updates, Threat Actor Glossary, Common Questions Q&A, Decision Ready Actions, Real World Examples, Source Summary, Source Deconfliction, Source Weighting, Contributors, and related PANDA index entries. Public-victim/disclosure search found no new reliable public organization notice that changed the victim matrix and did not promote Commvault's JavaScript-only trust-center shell, duplicate media recaps, generic OAuth commentary, leak-site-only claims, or unsupported Klue/Salesloft Drift conflation. Associated-campaign/activity-cluster search promoted Storm-3138 as Microsoft's Klue system-access activity label while preserving Icarus/ICARUS as the Klue-specific public extortion/operator label and keeping UNC6395/Salesloft Drift as comparator context. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained. Freshness labels applied to retained source-backed clarification: Newly retained (>24h). PANDA index date updated to Updated Jul 18, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.18 | July 19, 2026, 9:32 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, SEO rewrites, generic Salesforce/OAuth commentary, leak-site-only claims, social posts, JavaScript-only trust-center shells, source-index snippets without stable public bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Commvault remained a JavaScript-only Vanta trust-center shell without a stable inspectable disclosure body, and Insurity's July 9 status update remained represented by the retained Insurity citation without changing the analysis. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 19, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.18 | July 20, 2026, 9:32 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, recrawled summaries, SEO rewrites, generic Salesforce/OAuth commentary, leak-site-only claims, social posts, JavaScript-only trust-center shells, source-index snippets without stable public bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Sprout Social, Jamf, LastPass, Huntress, Tanium, Recorded Future, Insurity, and other retained notices remained represented by existing citations and boundaries. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 20, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.18 | July 21, 2026, 9:32 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, recrawled summaries, SEO rewrites, generic Salesforce/OAuth commentary, leak-site-only claims, social posts, JavaScript-only trust-center shells, source-index snippets without stable public bodies, aggregator victim tracking without direct organization-specific notice bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Commvault remained a JavaScript-only Vanta trust-center shell without a stable inspectable disclosure body, and VenariX aggregated victim tracking remained insufficient for new organization-specific impact-boundary rows without direct public notices. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 21, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.18 | July 22, 2026, 9:31 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, recrawled summaries, SEO rewrites, generic Salesforce/OAuth commentary, leak-site-only claims, social posts, JavaScript-only trust-center shells, search-index snippets without stable public bodies, aggregator victim tracking without direct organization-specific notice bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Commvault remained a JavaScript-only Vanta trust-center shell without a stable inspectable disclosure body despite current search snippets, and VenariX aggregated victim tracking remained insufficient for new organization-specific impact-boundary rows without direct public notices. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Microsoft and The Hacker News ShinyHunters/OAuth coverage remained represented by the existing retained Microsoft source and was not promoted as a duplicate delta. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 22, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.19 | July 23, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated source-backed direct customer-disclosure deltas. Newly retained (>24h): Greenhouse Software Trust Center Response to Klue Third-Party Security Incident, published/sent 24-Jun-2026 8:55 AM ET and retrieved 23-Jul-2026 9:31 PM ET, stating unauthorized access occurred on June 11 through Klue's integration, did not involve Greenhouse infrastructure, accessible data was limited to business contact information in sales/customer relationship systems, no Greenhouse product, hiring, or candidate data was affected, no modification or deletion was identified, and data protection authorities were notified; Blackbaud Trust Center Klue Security Incident Update, published 22-Jul-2026 4:05 PM ET and retrieved 23-Jul-2026 9:31 PM ET, stating Blackbaud's investigation remains ongoing with no substantive updates, no known Blackbaud product impact, and no business-operations/customer-service impact. Updated BLUF, Executive Summary, Timeline, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, Contributors, and related PANDA index review status. Public-victim/disclosure search found Greenhouse and Blackbaud direct notices and rejected Commvault/NetDocuments JavaScript-only trust-center shells, VenariX aggregator-only tracking without direct organization-specific public notice bodies, duplicate media recaps, SEO rewrites, generic OAuth commentary, leak-site-only claims, and unsupported Klue/Salesloft Drift conflation. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained. Freshness labels applied to retained sources: Newly retained (>24h). PANDA index date remained Updated Jul 23, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.20 | July 24, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated a source-backed direct customer-disclosure delta. Newly retained (publication date not visible): Confluent Trust Center Klue Security Incident - Confluent Statement, retrieved 24-Jul-2026 9:31 PM ET, stating Klue was used by Confluent sales and marketing teams, copied data was limited to Confluent business information stored in its CRM system such as business-contact and go-to-market opportunity information, data processed through Confluent products was not involved or impacted, and there is no indication Confluent products, platform, or infrastructure were affected. Updated BLUF, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, Contributors, and related PANDA index review status. Public-victim/disclosure search found Confluent's direct SafeBase trust-center notice and rejected Commvault/NetDocuments JavaScript-only shells, duplicate media/SEO rewrites, leak-site-only claims, generic OAuth commentary, and unsupported Klue/Salesloft Drift conflation. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. No Freshly reported (<24h) or Newly retained (>24h) source was retained. Freshness labels applied to retained sources: Newly retained (publication date not visible). PANDA index date updated to Updated Jul 24, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.20 | July 25, 2026, 9:31 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, recrawled summaries, SEO rewrites, generic Salesforce/OAuth commentary, leak-site-only claims, social posts, aggregator victim tracking without direct organization-specific public notice bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Confluent remained represented by the retained direct SafeBase notice, and VenariX/Tech Insider/ThreatLocker/Field Effect/SecurityBoulevard/Rescana/Nudge Security/QuoIntelligence coverage did not add organization-specific impact-boundary evidence. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date remained Updated Jul 25, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.20 | July 26, 2026, 9:31 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, recrawled summaries, SEO/blog rewrites, generic Salesforce/OAuth commentary, podcast/social posts, leak-site-only claims, aggregator victim tracking without direct organization-specific public notice bodies, search-index snippets without stable inspectable disclosure bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Commvault remained a JavaScript-only Vanta trust-center shell on direct retrieval despite current search snippets, NetDocuments remained unavailable to stable public inspection, and Confluent remained represented by the retained direct SafeBase notice. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Microsoft Storm-3138/ShinyHunters OAuth coverage remained represented by the retained Microsoft source. Freshness labels applied to retained sources: none. PANDA index date remained Updated Jul 26, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.20 | July 27, 2026, 9:30 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, recrawled summaries, SEO/blog rewrites, generic Salesforce/OAuth commentary, podcast/social posts, leak-site-only claims, aggregator victim tracking without direct organization-specific public notice bodies, search-index snippets without stable inspectable disclosure bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; LastPass remained represented by the retained direct LastPass response citation, Commvault still lacked a stable inspectable public body on direct retrieval despite current search snippets, NetDocuments remained unavailable to stable public inspection, and Confluent, Blackbaud, Greenhouse, Pendo, Cresta, Lucanet, Snyk, OneTrust, and other retained notices remained represented by existing citations and boundaries. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Microsoft Storm-3138/ShinyHunters OAuth coverage remained represented by the retained Microsoft source. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 27, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.21 | July 28, 2026, 9:32 PM ET | AI Monitoring Agent found and incorporated a source-backed direct no-impact disclosure delta. Newly retained (>24h): Autodesk Trust Center Bulletin: Important Security Notice Regarding Klue, published 23-Jun-2026 and retrieved 28-Jul-2026 9:32 PM ET, stating Klue notified Autodesk on June 16, the incident involved unauthorized access to Klue's third-party integration service and potentially affected Salesforce and Gong integrations, but Autodesk confirmed it does not use the Salesforce or Gong integrations for Klue and identified no direct impact to Autodesk products, services, or systems. Updated BLUF, Timeline, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, Contributors, and related PANDA index entries. Public-victim/disclosure search found Autodesk's direct no-impact advisory and rejected duplicate/SEO recaps, generic OAuth commentary, leak-site-only claims, social posts, JavaScript-only status shells without stable public bodies, and aggregator victim tracking without direct organization-specific public notice bodies. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained. Freshness labels applied to retained sources: Newly retained (>24h). PANDA index date updated to Updated Jul 28, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.21 | July 29, 2026, 9:31 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, recrawled summaries, SEO/blog rewrites, generic Salesforce/OAuth commentary, social posts, leak-site-only claims, aggregator victim tracking without direct organization-specific public notice bodies, search-index snippets without stable inspectable disclosure bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Commvault and NetDocuments remained JavaScript-only or empty on direct retrieval despite current search snippets, Autodesk remained represented by the retained direct no-impact advisory, and LastPass, Huntress, Jamf, Sprout Social, BeyondTrust, Snyk, Pendo, OneTrust, Confluent, Greenhouse, Blackbaud, Qualtrics, Splashtop, Saviynt, and other retained notices remained represented by existing citations and boundaries. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 29, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.22 | July 30, 2026, 9:32 PM ET | AI Monitoring Agent found and incorporated a source-backed primary restoration delta. Newly retained (>24h): Klue Integrations Restored: Salesforce and Gong Reconnected, published 27-Jul-2026 and retrieved 30-Jul-2026 9:32 PM ET, stating Salesforce and Gong reinstated Klue integrations in their marketplaces, all Klue integrations are available for customer enablement, and Klue added controls including static egress IPs allow-listed by Salesforce and Gong, platform-wide PKCE, tightened OAuth token lifecycle policies, elimination of GitHub personal access tokens, centralized monitoring and detection, runtime network filtering, and deployment-pipeline allowlist controls. Updated BLUF, Executive Summary, Timeline, AI Agent Delta Updates, Incident Response Playbook Ideas, Source Summary, Source Deconfliction, Citations, Contributors, and related PANDA index entries. Public-victim/disclosure search found no new reliable public organization notice requiring a victim-matrix change; retained direct notices continue to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision; CSA's July 16 note was not promoted because it was secondary/duplicative of already retained Microsoft and primary-source deconfliction. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained. Freshness labels applied to retained sources: Newly retained (>24h). PANDA index date updated to Updated Jul 30, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.23 | July 31, 2026, 9:32 PM ET | AI Monitoring Agent found and incorporated a source-backed primary engineering delta. Freshly reported (<24h): Klue What a Security Incident Taught Us About Securing a Modern SaaS Platform, published 31-Jul-2026 6:50 PM ET, modified 31-Jul-2026 6:54 PM ET, and retrieved 31-Jul-2026 9:32 PM ET, adding a more granular two-phase intrusion narrative, GitHub PAT source-code access and second PAT discovery, credential testing, unauthorized build/deployment path, tampered production workload, stored OAuth-token access, June 12 containment, CrowdStrike no-post-containment-activity finding, GitHub/CI-CD hardening, default-deny network controls, OAuth refresh-token rotation or idle expiration, IP-range allow-listing, integration least-privilege guidance, and distributed-evidence response lessons. Klue Integrations Restored: Salesforce and Gong Reconnected was also observed with a 31-Jul-2026 6:51 PM ET modification timestamp and HubSpot marketplace wording, but the restoration posture remained represented by the existing v1.22 source. Updated Klue Exposure Snapshot, BLUF, Executive Summary, Timeline, AI Agent Delta Updates, Incident Response Playbook Ideas, Source Summary, Source Deconfliction, Citations, Contributors, and related PANDA index entries. Public-victim/disclosure search found no new reliable public organization notice requiring a victim-matrix change; Commvault and NetDocuments remained JavaScript-only trust-center shells without stable inspectable disclosure bodies, and retained direct notices continue to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. No Newly retained (>24h) or Newly retained (publication date not visible) source was retained. Freshness labels applied to retained source: Freshly reported (<24h). PANDA index date updated to Updated Jul 31, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.23 | August 1, 2026, 9:32 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, recrawled summaries, SEO/blog rewrites, generic Salesforce/OAuth commentary, social posts, leak-site-only claims, aggregator-only victim tracking without direct organization-specific public notice bodies, search-index snippets without stable inspectable disclosure bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Insurity's July 9 status update, Autodesk's no-impact advisory, LastPass, Huntress, Jamf, Sprout Social, BeyondTrust, Snyk, Pendo, OneTrust, Confluent, Greenhouse, Blackbaud, Qualtrics, Splashtop, Saviynt, and other retained notices remained represented by existing citations and boundaries. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date already showed Updated Aug 1, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.24 | August 2, 2026, 9:32 PM ET | AI Monitoring Agent found and incorporated a source-backed direct customer-disclosure delta. Newly retained (publication date not visible): Yext Trust Center Klue Security Incident, retrieved 02-Aug-2026 9:32 PM ET, stating stolen Klue-held credentials were used to run read-only queries against Yext's internal Salesforce CRM for roughly 17 hours on June 11-12, exposing business contact details for customers and prospects, while Yext excluded platform, product, infrastructure, customer-content, customer-facing-system, end-user-data, payment-card, Google Workspace, and Slack impact. Updated BLUF, Executive Summary, Timeline, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, Contributors, and page metadata. Public-victim/disclosure search found Yext's direct SafeBase trust-center notice and rejected duplicate or secondary recaps, generic OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking, and Commvault/NetDocuments JavaScript-only or empty direct retrievals without stable inspectable public bodies. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. No Freshly reported (<24h) or Newly retained (>24h) source was retained. Freshness labels applied to retained sources: Newly retained (publication date not visible). PANDA index date already showed Updated Aug 2, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.25 | August 3, 2026, 9:32 PM ET | AI Monitoring Agent found and incorporated source-backed direct customer-disclosure deltas. Newly retained (>24h): Commvault Trust Center Klue Security Update: What Happened and What Customers Should Know, published 13-Jul-2026 and retrieved 03-Aug-2026 9:32 PM ET, stating Commvault used Klue, removed the integration, contained unauthorized access, and limited accessed data to Salesforce business relationship and sales activity information while excluding customer data, Commvault solutions/services, customer backup data, product metadata, and logs; NetDocuments TrustShare The NetDocuments Service Not Impacted by Klue Security Incident, published 26-Jun-2026 3:20 PM ET and retrieved 03-Aug-2026 9:32 PM ET, stating Klue-related impact was limited to internal Gong-user staff-list data while excluding customer data, prospective customer data, Customer Repository Data, and NetDocuments Service impact. Updated BLUF, Executive Summary, Timeline, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, Contributors, page metadata, and related PANDA index entries. Public-victim/disclosure search found Commvault and NetDocuments rendered public notices and rejected duplicates, SEO recaps, generic OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking, and unsupported Salesforce/OAuth attribution rewrites. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained. Freshness labels applied to retained sources: Newly retained (>24h). PANDA index date updated to Updated Aug 3, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.26 | August 4, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated a source-backed direct customer-disclosure delta. Newly retained (>24h): Neon One Notice of Data Breach, dated 31-Jul-2026 and retrieved 04-Aug-2026 9:31 PM ET, stating Neon One became aware on 16-Jun-2026 of a Klue cybersecurity incident involving an integration service for Neon One's Salesforce customer relationship management software, resulting in unauthorized access to some personal information between 11-Jun-2026 and 12-Jun-2026, with the incident contained and no further impact identified. Updated BLUF, Executive Summary, Timeline, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, page metadata, and related PANDA index entries. Public-victim/disclosure search found Neon One's direct notice letter and rejected the ClaimDepot Klue recap as duplicative/partly inconsistent with primary Klue timing, generic legal SEO recaps, duplicate media, generic OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking, and unsupported Salesforce/OAuth attribution rewrites. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained. Freshness labels applied to retained source: Newly retained (>24h). PANDA index date updated to Updated Aug 4, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.26 | August 6, 2026, 9:31 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, recrawled summaries, SEO/blog rewrites, generic Salesforce/OAuth commentary, social posts, leak-site-only claims, aggregator-only victim tracking without direct organization-specific public notice bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Snyk, Cresta, Insurity, Recorded Future, eSentire, Neon One, Yext, Commvault, NetDocuments, Autodesk, LastPass, Huntress, Jamf, Sprout Social, BeyondTrust, OneTrust, Confluent, Pendo, Camunda, Saviynt, and other retained notices remained represented by existing citations and organization-specific boundaries. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 6, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.26 | August 7, 2026, 9:35 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, recrawled summaries, SEO/blog rewrites, generic Salesforce/OAuth commentary, social posts, leak-site-only claims, aggregator-only victim tracking without direct organization-specific public notice bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Snyk's rendered trust-center Klue closure remains the already retained July 8 update, the August 5 Snyk trust-center result concerned a separate npm supply-chain incident, and retained direct notices remained represented by existing citations and organization-specific boundaries. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 7, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.26 | August 8, 2026, 9:31 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, recrawled summaries, SEO/blog rewrites, generic Salesforce/OAuth commentary, social posts, leak-site-only claims, aggregator-only victim tracking without direct organization-specific public notice bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Insurity's current status result remains the already retained July 9 update, Snyk's rendered trust-center Klue closure remains the already retained July 8 update, Neon One remains represented by the retained July 31 notice letter, and retained direct notices remained represented by existing citations and organization-specific boundaries. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date already showed Updated Aug 8, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.26 | August 9, 2026, 9:32 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, recrawled summaries, SEO/blog rewrites, generic Salesforce/OAuth commentary, social posts, leak-site-only claims, aggregator-only victim tracking without direct organization-specific public notice bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Insurity's current status content remains the already retained July 9 update, Thinkproject's August 5 status text did not change its retained UAT CRM/product-boundary analysis, Cresta/Pendo/Snyk and other retained notices remained represented by existing citations and organization-specific boundaries, and Delinea/Obsidian/ThreatLocker/Field Effect/Zscaler/Kudelski/Rescana/RH-ISAC/CSA/Microsoft/The Hacker News recap or comparator coverage did not add a Klue-specific source-backed delta. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 9, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.27 | August 10, 2026, 9:36 PM ET | AI Monitoring Agent found and incorporated a source-backed direct customer-disclosure delta. Newly retained (>24h): Massachusetts Attorney General Data Breach Notification Portal / Betterment 2026-1291 - Betterment PDF, published 05-Aug-2026 and retrieved 10-Aug-2026 9:36 PM ET, stating Klue Labs Inc. was a vendor used by Betterment's sales team and had access to a Salesforce database containing Betterment information. Updated BLUF, Timeline, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, Contributors, page metadata, and page version. Public-victim/disclosure search found Betterment's regulator-hosted public notice-letter PDF and rejected duplicate legal SEO recaps, unrelated January Betterment/ShinyHunters reporting, generic Salesforce/OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking, and unsupported Salesforce/OAuth attribution rewrites. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained. Freshness labels applied to retained source: Newly retained (>24h). PANDA index date already showed Updated Aug 10, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.28 | August 11, 2026, 9:30 PM ET | AI Monitoring Agent incorporated a source-backed public notice scoping delta from an already-retained primary PDF. Newly retained (>24h): Massachusetts Attorney General Data Breach Notification Portal / Betterment 2026-1291 - Betterment PDF, published 05-Aug-2026, originally retrieved 10-Aug-2026 9:36 PM ET, and PDF text re-reviewed 11-Aug-2026 9:30 PM ET, clarifying that unauthorized access involved a file containing name and Social Security number, that Betterment's computer systems were not accessed, and that two years of Kroll identity monitoring were offered. Updated BLUF, Timeline, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, Contributors, page metadata, page version, and related PANDA index entries. Public-victim/disclosure search found no new named organization beyond retained sources; Dapeer and other legal/SEO recaps were treated as duplicate secondary coverage and not retained as source deltas. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained. Freshness labels applied to the source-backed re-review: Newly retained (>24h). PANDA index date updated to Updated Aug 11, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.28 | August 12, 2026, 9:30 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate legal/SEO recaps, recrawled primary notices, generic Salesforce/OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking without direct organization-specific public notice bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF and Dapeer remains duplicate legal/SEO commentary derived from that notice. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. BleepingComputer City-Forum Salesforce/ServiceNow portal reporting was treated as separate guest-portal exposure context and not promoted into the Klue brief. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 12, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.28 | August 13, 2026, 9:31 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate legal/SEO recaps, recrawled primary notices, generic Salesforce/OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking without direct organization-specific public notice bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Neon One remains represented by the retained July 31 notice letter, and Dapeer, ClaimDepot, ClassActionU, and similar legal/SEO recaps were treated as duplicate secondary commentary rather than new source-backed deltas. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 13, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.28 | August 14, 2026, 9:31 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate legal/SEO recaps, recrawled primary notices, generic Salesforce/OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking without direct organization-specific public notice bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Commvault remains represented by the retained trust-center boundary and the July 24 Commvault blog was treated as duplicate context, Snyk's current trust-center result concerned a separate npm supply-chain incident, and retained direct notices continued to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 14, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.28 | August 15, 2026, 9:32 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate legal/SEO recaps, recrawled primary notices, generic Salesforce/OAuth commentary, leak-site-only claims, social posts, aggregator-only victim tracking without direct organization-specific public notice bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Snyk's current trust-center result remains the already retained Klue closure or separate npm incident context, Delinea/CSA/Mitiga/Dark Reading/BlackFog/Rescana/RH-ISAC/Kudelski/SOCRadar/Beazley/TechCrunch/The Hacker News/SecurityWeek/LinkedIn/social recaps did not add organization-specific impact-boundary evidence, and retained direct notices continued to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 15, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.29 | August 16, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated a source-backed public status-resolution delta. Newly retained (>24h): Thinkproject Status Klue Breach that Allowed Data Exfiltration from Salesforce, updated/resolved 12-Aug-2026 2:01 PM and retrieved 16-Aug-2026 9:31 PM ET, stating Thinkproject's investigation has concluded, Thinkproject is not aware of misuse of the affected data, and monitoring continues while preserving its existing UAT CRM, possible business-contact/commercial-information, no-product-or-service-impact, and customer product-platform separation boundary. Updated BLUF, Timeline, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, Contributors, page metadata, and page version. Public-victim/disclosure search found Thinkproject's direct status resolution and rejected duplicate secondary recaps, generic Salesforce/OAuth commentary, legal/SEO rewrites, leak-site-only claims, social posts, and aggregator-only victim tracking without direct organization-specific public notice bodies. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained. Freshness labels applied to retained source: Newly retained (>24h). PANDA index date already showed Updated Aug 16, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.29 | August 17, 2026, 9:32 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, recrawled primary notices, SEO/blog rewrites, generic Salesforce/OAuth commentary, Delinea's August 2026 Drift-to-Klue recap, legal recap pages, social posts, leak-site-only claims, aggregator-only victim tracking without direct organization-specific public notice bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Thinkproject remains represented by the retained Aug. 12 status resolution, Snyk's rendered trust-center Klue closure remains retained, and retained direct notices continued to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 17, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.29 | August 18, 2026, 9:31 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, recrawled primary notices, SEO/blog rewrites, generic Salesforce/OAuth commentary, Delinea's August 2026 Drift-to-Klue recap and similar explainers, legal recap pages, social posts, leak-site-only claims, aggregator-only victim tracking without direct organization-specific public notice bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Thinkproject remains represented by the retained Aug. 12 status resolution, and retained direct notices continued to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 18, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.29 | August 19, 2026, 9:31 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, recrawled primary notices, SEO/legal recaps, generic Salesforce/OAuth and non-human-identity commentary, social posts, leak-site-only claims, aggregator-only victim tracking without direct organization-specific public notice bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Thinkproject remains represented by the retained Aug. 12 status resolution, Neon One remains represented by the retained Nebraska AG notice letter, and retained direct notices continued to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date already showed Updated Aug 19, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.29 | August 20, 2026, 9:31 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, recrawled primary notices, product/news posts unrelated to the incident, generic Salesforce/OAuth and non-human-identity commentary, social posts, leak-site-only claims, aggregator-only victim tracking without direct organization-specific public notice bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Thinkproject remains represented by the retained Aug. 12 status resolution, Neon One remains represented by the retained Nebraska AG notice letter, and retained direct notices continued to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date already showed Updated Aug 20, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.29 | August 21, 2026, 9:32 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, recrawled primary notices, generic Salesforce/OAuth and non-human-identity commentary, legal/SEO recap pages, social posts, leak-site-only claims, aggregator-only victim tracking without direct organization-specific public notice bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Thinkproject remains represented by the retained Aug. 12 status resolution, Neon One remains represented by the retained Nebraska AG notice letter, and retained direct notices continued to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 21, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v1.29 | August 22, 2026, 9:32 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, recrawled primary notices, aggregate breach lists, generic Salesforce/OAuth and non-human-identity commentary, legal/SEO recap pages, social posts, leak-site-only claims, aggregator-only victim tracking without direct organization-specific public notice bodies, and unsupported Icarus/UNC6395/Salesloft Drift/Gainsight/ShinyHunters/Storm-3138 conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Thinkproject remains represented by the retained Aug. 12 status resolution, Neon One remains represented by the retained Nebraska AG notice letter, and retained direct notices continued to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date already showed Updated Aug 22, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v1.29 | August 23, 2026, 9:33 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, recrawled primary notices, aggregate breach lists, generic Salesforce/OAuth and non-human-identity commentary, legal/SEO recap pages, social posts, leak-site-only claims, aggregator-only victim tracking without direct organization-specific public notice bodies, and unsupported Icarus/UNC6395/Salesloft Drift/Gainsight/ShinyHunters/Storm-3138 conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Thinkproject remains represented by the retained Aug. 12 status resolution, Neon One remains represented by the retained Nebraska AG notice letter, and retained direct notices continued to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 23, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v1.29 | August 24, 2026, 9:32 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, recrawled primary notices, search-result snippets without new inspectable direct notice bodies, aggregate breach lists, generic Salesforce/OAuth and non-human-identity commentary, legal/SEO recap pages, social posts, leak-site-only claims, aggregator-only victim tracking without direct organization-specific public notice bodies, and unsupported Icarus/UNC6395/Salesloft Drift/Gainsight/ShinyHunters/Storm-3138 conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Thinkproject remains represented by the retained Aug. 12 status resolution, Neon One remains represented by the retained Nebraska AG notice letter, and retained direct notices continued to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 24, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v1.29 | August 25, 2026, 9:32 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, recrawled primary notices, Klue product posts unrelated to the security incident, search-result snippets without new inspectable direct notice bodies, aggregate breach lists, generic Salesforce/OAuth and non-human-identity commentary, legal/SEO recap pages, social posts, leak-site-only claims, aggregator-only victim tracking without direct organization-specific public notice bodies, and unsupported Icarus/UNC6395/Salesloft Drift/Gainsight/ShinyHunters/Storm-3138 conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Betterment remains represented by the retained Mass.gov primary PDF, Thinkproject remains represented by the retained Aug. 12 status resolution, Neon One remains represented by the retained Nebraska AG notice letter, and retained direct notices continued to control each organization's boundary. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 25, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
30-Citations
Baseline Sources Answering The Topic Question
| # | Source | Publisher | Published | Why Used |
|---|---|---|---|---|
| 1 | An Update on the Recent Klue Security Incident | Klue | June 22, 2026 | Primary vendor statement confirming unauthorized activity affecting part of Klue integration infrastructure, a compromised legacy integration credential, OAuth tokens used to connect Klue with Salesforce, customer-environment access, token revocation, integration disablement, and law-enforcement notification. |
| 2 | Update on Recent Salesforce Data Theft Incidents | Salesforce | June 2026 | Official Salesforce ecosystem context: malicious activity tied to third-party application connections and social-engineering/OAuth abuse, with no Salesforce platform vulnerability identified. |
| 3 | LastPass Update on Klue Customer Data Incident | LastPass | June 2026 | Primary downstream-customer notice: LastPass says Klue notified it of a Salesforce-related incident and states LastPass product systems and vaults were not compromised. |
| 4 | LastPass confirms data breach in Klue supply chain attack | BleepingComputer | June 23, 2026 | Starter public report connecting LastPass customer-data exposure to Klue as a third-party vendor and summarizing the supply-chain framing for a broad security audience. |
| 5 | Klue Integration Abused in Salesforce Data Theft | ReliaQuest | June 22, 2026 | Technical and operational reporting on Klue Battlecards integration abuse, OAuth tokens, Salesforce REST API queries, observed exfiltration, Python automation, attribution caveats, and response priorities. |
| 6 | Detecting the Klue supply chain attack in Salesforce instances | Datadog Security Labs | June 2026 | Detection-focused reporting on Klue/Salesforce activity, compromised connected application identification, OAuth refresh token usage, REST API query patterns, timelines, event types, and hunting logic. |
| 7 | Klue: Salesforce Data Impacted for Many Victims, including Huntress | Huntress | June 18, 2026 | Victim/researcher account documenting downstream Salesforce impact, broad victim implications, OAuth-token abuse, and practical investigation guidance. |
| 8 | Klue investigates supply-chain attack involving Salesforce integrations | Cybersecurity Dive | June 20, 2026 | Security trade reporting on anomalous activity in Klue's Salesforce integration application, token revocation, and customer notification posture. |
| 9 | Third-Party OAuth Breach Exposes Customer Data | The Hacker News | June 2026 | Corroborating security-media coverage of third-party OAuth risk and downstream customer exposure in the Klue/Salesforce incident. |
| 10 | Klue Salesforce data breach impacts many downstream customers | Help Net Security | June 19, 2026 | Corroborating public reporting on downstream organizations and the broader Salesforce integration exposure narrative. |
| 11 | Klue Breach Impact on Jamf | Jamf Trust Center | June 2026 | Downstream customer signal used to show that Klue customers beyond LastPass published their own impact assessments. |
| 12 | Klue Security Incident | Sprout Social Trust Center | June 2026 | Downstream customer trust-center signal used to show notification and impact-scoping patterns among Klue customers. |
| 13 | Connected App Overview | Salesforce Help | Living documentation | Authoritative platform documentation for connected apps and OAuth-style trust relationships in Salesforce environments. |
| 14 | T1199 - Trusted Relationship | MITRE ATT&CK | Living framework | Framework mapping for adversary use of third-party trust relationships to reach a target environment. |
| 15 | T1528 - Steal Application Access Token | MITRE ATT&CK | Living framework | Framework mapping for stealing or abusing application access tokens. |
| 16 | T1078 - Valid Accounts | MITRE ATT&CK | Living framework | Framework mapping for continued access through valid account or service-account style authentication. |
| 17 | T1567.002 - Exfiltration to Cloud Storage | MITRE ATT&CK | Living framework | Framework-adjacent exfiltration mapping for cloud/API-mediated data movement where supported by local Salesforce telemetry. |
| 25 | EventLogFile | Object Reference for the Salesforce Platform | Salesforce Developers | Living documentation | Official Salesforce developer documentation for EventLogFile, the object used to access event monitoring data for Salesforce operational and security investigations. |
| 26 | EventLogFile Supported Event Types | Salesforce Developers | Living documentation | Official Salesforce reference for event types such as REST API, API Total Usage, Bulk API, Login, Report, Report Export, Permission Update, and related forensic event categories. |
| 27 | Monitor Setup Changes with Setup Audit Trail | Salesforce Help | Living documentation | Official Salesforce guidance for Setup Audit Trail, used to investigate administrative, connected-app, permission, and configuration changes during a Salesforce incident. |
| 28 | Monitor Login History | Salesforce Help | Living documentation | Official Salesforce guidance for reviewing login history, including who logged in, when, and from where. |
| 29 | T1119 - Automated Collection | MITRE ATT&CK | Living framework | Framework mapping for automated collection behavior, used where Salesforce API query volume and object enumeration support collection activity. |
| 30 | Klue Supply Chain Incident & LastPass Response | LastPass | June 22, 2026 | Newly retained (>24h) primary downstream-customer response clarifying LastPass's Salesforce and Gong integration context, OAuth-token exposure, impacted data categories, token rotation, discontinued Klue access, law-enforcement cooperation, customer anti-phishing guidance, published IOCs, and product/vault boundary. |
| 31 | Hacked Klue says criminals are deleting stolen customer data, but now other hackers are making threats | TechCrunch | June 25, 2026 | Freshly reported (<24h) update that Klue said the original criminals were deleting stolen customer data while a second group was making threats, changing the extortion and customer-communications posture. |
| 32 | BeyondTrust, LastPass Impacted by Klue-Salesforce Incident | SecurityWeek | June 24, 2026 | Newly retained (>24h) reporting that over a dozen Klue customers had confirmed Salesforce-instance data theft and that BeyondTrust and LastPass were among impacted organizations. |
| 33 | When a vendor's breach becomes yours: lessons from the Klue incident | Snyk | June 23, 2026 | Newly retained (>24h) downstream-customer disclosure describing Salesforce business data impact and support-case title/description boundaries. |
| 34 | Security Advisory: HackerOne's Response to the Klue Breach | HackerOne | June 2026 | Newly retained (>24h) downstream-customer advisory describing Klue disconnection, Salesforce access disablement, credential/log review, and isolation of exposure to Salesforce. |
| 35 | Klue Security Incident | BeyondTrust | June 2026 | Newly retained (>24h) downstream-customer notice confirming Klue as a competitive intelligence vendor integrated with BeyondTrust's Salesforce CRM and describing access to business contact and general sales-related customer information. |
| 36 | More Klue Breach Victims Identified as Hackers Get Hacked | SecurityWeek | June 26, 2026, 11:01 AM ET | Freshly reported (<24h) follow-up naming additional public customer-notice examples, reporting roughly two dozen confirmed Klue-Salesforce impact disclosures, preserving Salesforce/Gong disablement context, and caveating second-actor possession claims. |
| 37 | Technical Analysis of the Klue Attack: OAuth Abuse, Stale Integrations, and Salesforce Exfiltration | Obsidian Security | June 25, 2026 | Newly retained (>24h) technical analysis across impacted organizations, adding Global Describe reconnaissance, QueryMore pagination, API-version downgrade, user-agent deviation, source-infrastructure deviation, object-harvest scope, and Icarus/UNC6395 deconfliction. |
| 38 | Security update: Klue breach and impact on Pendo | Pendo | June 22, 2026 | Newly retained (>24h) direct customer disclosure confirming Pendo Salesforce CRM access through Klue, affected business/contact data, product-platform boundary, response steps, and anti-phishing guidance. |
| 39 | The Klue Security Incident and Its Impact on Recorded Future | Recorded Future | Publication date not visible | Newly retained (publication date not visible) direct customer disclosure confirming Recorded Future Salesforce impact through a Klue OAuth token while preserving its core platform, Intelligence Graph, and infrastructure boundary. |
| 40 | Form 8-K for 8x8 Inc. filed 06/23/2026 | 8x8 | June 23, 2026 | Newly retained (>24h) regulatory disclosure confirming unauthorized access to 8x8 Salesforce through the Klue integration, June 11-12 access, customer/prospect commercial and contact data categories, containment, and operational-impact boundary. |
| 41 | Security Advisory: Third-Party Security Incident Involving Klue | LogicMonitor | June 26, 2026 | Newly retained (>24h); retrieved 27-Jun-2026 9:33 PM ET. Direct customer disclosure confirming unauthorized access to the Catchpoint Salesforce environment through Klue, while preserving the boundary that LogicMonitor's primary Salesforce environment and production/monitoring systems were not impacted. |
| 42 | Tines Trust Center - Klue Incident Notice | Tines Trust Center | Publication date not visible | Newly retained (publication date not visible); retrieved 27-Jun-2026 9:33 PM ET. Direct customer trust-center notice stating Tines was notified that Klue credentials were used to access Salesforce data and that Tines found no evidence of unauthorized access to the Tines platform or customer environments. |
| 43 | Security Update: Tanium's Response to the Klue Breach that Allowed Data Exfiltration from Salesforce | Tanium | June 18, 2026 | Newly retained (>24h); retrieved 27-Jun-2026 9:33 PM ET. Direct customer disclosure describing Tanium Salesforce CRM data exfiltration through Klue and preserving the boundary that Tanium products and cloud infrastructure were not impacted. |
| 44 | Update From OneTrust on Klue Security Incident | OneTrust | June 24, 2026; updated July 10, 2026 | Newly retained (>24h); retrieved 28-Jun-2026 9:31 PM ET; July 10 update retrieved 11-Jul-2026 9:31 PM ET. Direct customer disclosure confirming Klue Battlecards/Salesforce CRM-related data exposure, June 11-12 activity, Salesforce API/log review, disabled Klue integration, no evidence of passwords, payment cards, customer tenant data, or customer-managed OneTrust environment exposure, and July 10 investigation completion with no evidence of exposure beyond OneTrust's Salesforce environment. |
| 45 | Klue Security Incident | Gong | June 19, 2026 | Newly retained (>24h); retrieved 28-Jun-2026 9:31 PM ET. Direct platform-provider disclosure stating the incident originated with Klue, affected customers were those who connected Klue with Gong, a subset may have had licensed-user business data accessed, and Gong found no direct impact to call recordings or customer transcripts. |
| 46 | Notification of Salesforce / Klue Security Incident | Insurity Status | June 18, 2026; updated June 22, 2026 | Newly retained (>24h); retrieved 28-Jun-2026 9:31 PM ET. Direct customer status notice confirming Salesforce notified Insurity of suspicious activity involving its Klue connected application, later identifying a very limited set of active credentials in exposed CRM data, rotating or resetting those secrets, and stating Insurity products were not involved. |
| 47 | Third-Party Security Incident - Klue-Salesforce Integration | AudienceView Status | June 29, 2026; initial monitoring June 22, 2026 | Freshly reported (<24h) status resolution; retrieved 29-Jun-2026 9:31 PM ET. Direct customer status notice confirming AudienceView impact through the Klue-Salesforce integration while preserving product, production-system, internal-system, and patron-data boundaries. |
| 48 | Security Incident at Third-Party Provider Klue: Certain Link11 CRM Data Affected | Link11 | June 25, 2026 | Newly retained (>24h); retrieved 29-Jun-2026 9:31 PM ET. Direct customer disclosure confirming Link11 used a Klue OAuth-based Salesforce CRM integration and that certain business contact and sales-related CRM data was affected. |
| 49 | AlertMedia Trust Center - Klue Incident Update | AlertMedia Trust Center | Publication date not visible | Newly retained (publication date not visible); retrieved 29-Jun-2026 9:31 PM ET. Direct trust-center notice stating AlertMedia disabled Klue, revoked access, rotated third-party Salesforce integration credentials, and found no AlertMedia platform customer data or product-supporting systems impact. |
| 50 | Klue/Salesforce Security Breach - Investigation Update | Camunda Trust Center | July 1, 2026, 6:00 PM ET | Newly retained (>24h); retrieved 02-Jul-2026 9:31 PM ET. Direct trust-center update revising Camunda's Klue/Salesforce impact boundary: exfiltrated data did not include support data and was limited to standard business-contact and account information in Salesforce CRM. |
| 51 | Cresta Trust Center - Klue Incident Update | Cresta Trust Center | Publication date not visible | Newly retained (publication date not visible); retrieved 29-Jun-2026 9:31 PM ET. Direct trust-center notice confirming Cresta's Salesforce instance was impacted, possible exposure of business contact information, contractual information, and email correspondence, and no indication of Cresta product or infrastructure impact. |
| 52 | Lucanet Trust Center - Klue Incident Notice | Lucanet Trust Center | Publication date not visible | Newly retained (publication date not visible); retrieved 29-Jun-2026 9:31 PM ET. Direct trust-center notice stating Lucanet's internally used Klue competitive-intelligence tool was affected, supporting Lucanet as a direct customer disclosure without expanding the impact beyond that notice. |
| 53 | Cybersecurity Alert: Klue OAuth Breach and Salesforce Data Exfiltration | FINRA | June 26, 2026 | Newly retained (>24h); retrieved 29-Jun-2026 9:31 PM ET. Sector-facing guidance naming Icarus, OAuth-token theft across Salesforce and other SaaS integrations, additional affected organizations, suspicious IPs and sender domains, and member-firm mitigation priorities. |
| 54 | ZeroFox Intelligence Profile - ICARUS | ZeroFox | June 26, 2026 | Newly retained (>24h); retrieved 29-Jun-2026 9:31 PM ET. Actor profile assessing ICARUS as a financially motivated extortion group active since late April or early May 2026, adding the Underground Uwu/SLH caveat, operational-maturity assessment, and Klue-linked victimology and IOCs. |
| 55 | Klue Third-Party Cybersecurity Incident | ControlUp | June 26, 2026 | Newly retained (>24h); retrieved 30-Jun-2026 9:31 PM ET. Direct customer disclosure confirming unauthorized access to certain ControlUp Salesforce business data through Klue's integration while preserving boundaries for ControlUp solutions, production environment, and infrastructure. |
| 56 | Klue security incident - Deel impact | Deel | June 25, 2026; last update June 26, 2026 | Newly retained (>24h); retrieved 30-Jun-2026 9:31 PM ET. Direct customer disclosure confirming unauthorized access to a portion of public, business-contact, and commercial information in Deel's CRM environment while excluding the Deel platform itself. |
| 57 | Security Update - Klue Third-Party Cybersecurity Incident | Saviynt Trust Portal | June 23, 2026 | Newly retained (>24h); retrieved 30-Jun-2026 9:31 PM ET. Direct trust-portal notice stating Saviynt was one of the impacted customers, potential impact was limited to certain sales data in Salesforce, and Saviynt products, services, and product customer data were not impacted. |
| 58 | A message to our customers about the Klue security incident | ABBYY Trust Center | Publication date not visible | Newly retained (publication date not visible); retrieved 30-Jun-2026 9:31 PM ET. Direct trust-center notice stating Salesforce data accessed through Klue's integration was affected while ABBYY's network, products, and technology were not affected. |
| 59 | CrowdStrike Investigation Summary and Security Improvements | Klue | July 2, 2026, 12:02 AM ET (page byline July 1, 2026) | Freshly reported (<24h); retrieved 02-Jul-2026 9:31 PM ET. Primary Klue/CrowdStrike investigation summary stating a previously compromised GitHub personal access token introduced unauthorized code into Klue's integration service, collected third-party integration credentials including Salesforce OAuth access and refresh tokens, and adding containment, scope, monitoring, and CI/CD hardening details. |
| 60 | Notice of Security Incident | Postman Security & Trust Portal | Publication date not visible; incident confirmation dated June 17, 2026 | Newly retained (publication date not visible); retrieved 04-Jul-2026 9:31 PM ET. Direct trust-portal notice confirming Postman customer contact and sales information was exfiltrated from Salesforce via the compromised Klue service account between June 11-12, while customer data was not accessed from Gong and Postman's core platform services were not impacted. |
| 61 | Klue Security Incident | Automox Trust Center | June 29, 2026 | Newly retained (>24h); retrieved 05-Jul-2026 9:31 PM ET. Direct trust-center notice stating Automox used Klue with Salesforce, reviewed internal logs and Salesforce Login History/Connected App OAuth usage, found no anomalous or malicious activity, and says Klue confirmed it had no indication Automox data or customer data was affected. |
| 62 | Responding to the Klue Incident: Practical Steps to Audit and Harden Your Integrations | eSentire | June 26, 2026 | Newly retained (>24h); retrieved 07-Jul-2026 9:32 PM ET. Direct customer disclosure stating eSentire uses Klue, was among organizations whose Salesforce data was accessed, characterizes its exposure as minimal, and excludes customer-service risk, customer communications, support interactions, threat intelligence, telemetry, credentials, passwords, and payment-card data. |
| 63 | Klue Breach that Allowed Data Exfiltration from Salesforce | Thinkproject Status | June 26, 2026, 6:47 AM; resolved August 12, 2026, 2:01 PM | Newly retained (>24h); initially retrieved 08-Jul-2026 9:32 PM ET and resolution update retrieved 16-Aug-2026 9:31 PM ET. Direct customer status notice stating Klue had authorized access to Thinkproject's UAT CRM environment through a software integration, exfiltrated data may include business-contact and commercial information, Thinkproject products and services were not affected, the CRM system is separate from the customer product platform, the investigation has concluded, Thinkproject is not aware of misuse of affected data, and monitoring continues. |
| 64 | Third-Party Vendor Security Incident (Klue) | Snyk Status | July 8, 2026, 11:26 AM ET | Newly retained (>24h); retrieved 09-Jul-2026 9:31 PM ET. Official Snyk status resolution stating its Mandiant-assisted forensic investigation into the Klue/Salesforce incident is complete, impact was limited to business CRM data, and no Snyk platform or sensitive platform data impact was found. |
| 65 | SentinelOne Confirms Klue Supply Chain Incident Contained to Salesforce | Secure ISS | July 9, 2026 | Freshly reported (<24h); retrieved 09-Jul-2026 9:31 PM ET. Public advisory relaying SentinelOne's partner notification that the Klue impact was contained to SentinelOne's Salesforce environment through the Klue API integration, with no lateral movement, core-product, cloud-infrastructure, or production-environment impact reported; data analysis remains ongoing. |
| 66 | Defending SaaS-based applications against ShinyHunters OAuth abuse | Microsoft Security Research / Microsoft Defender Security Research Team | July 13, 2026 | Freshly reported (<24h); retrieved 13-Jul-2026 9:31 PM ET. Microsoft research grouping mid-2025 to mid-2026 Salesforce/SaaS OAuth abuse tradecraft commonly associated with ShinyHunters, while including a Klue integration IP used for Salesforce API CRM queries on June 11 and reinforcing that trusted OAuth relationships, not a Salesforce platform vulnerability, drove the risk. |
| 67 | Security Update: Klue Security Incident | Sisense Trust Center | Publication date not visible | Newly retained (publication date not visible); retrieved 14-Jul-2026 9:32 PM ET. Direct trust-center notice stating Sisense was one of many affected organizations, limiting the incident to certain business and sales-related data in Sisense's Salesforce CRM application, excluding Sisense product-platform data, and noting credential/token rotation and access-log monitoring. |
| 68 | Klue Supply Chain Compromise: Qualtrics Response | Qualtrics XM Trust Center | June 25, 2026, 12:55 UTC | Newly retained (>24h); retrieved 16-Jul-2026 9:32 PM ET. Direct trust-center notice stating Klue connected to Salesforce for Qualtrics internal sales-team support, unauthorized access was limited to a subset of Salesforce data, impacted data included business-to-business identifiers, and Qualtrics products, core infrastructure, services, and hosted platform customer data were not accessed or compromised. |
| 69 | Security Update Regarding Third-Party Klue Incident | Splashtop | Updated June 30, 2026 | Newly retained (>24h); retrieved 16-Jul-2026 9:32 PM ET. Direct customer update stating Klue's environment was compromised, OAuth tokens were used to access certain Salesforce data, Splashtop disabled the Klue Salesforce integration and revoked access, investigation remained ongoing, and Splashtop products, services, and customer-support ability were not impacted. |
| 70 | Response to Klue Third-Party Security Incident | Greenhouse Software Trust Center | June 24, 2026, 8:55 AM ET | Newly retained (>24h); retrieved 23-Jul-2026 9:31 PM ET. Direct Conveyor trust-center notice stating attackers obtained Klue credentials used to connect to certain Greenhouse business systems, unauthorized access occurred on June 11, was scoped to Klue's integration, did not involve Greenhouse infrastructure, accessible data was limited to business contact information in sales/customer relationship systems, no Greenhouse product, hiring, or candidate data was affected, no modification or deletion was identified, and relevant data protection authorities were notified. |
| 71 | Klue Security Incident Update | Blackbaud Trust Center | July 22, 2026, 4:05 PM ET; initial notice June 24, 2026, 8:55 AM ET | Newly retained (>24h); retrieved 23-Jul-2026 9:31 PM ET. Direct Conveyor trust-center update stating Blackbaud's Klue-related investigation remains ongoing with no substantive updates, no known impact to Blackbaud products, and no impact to business operations or ability to serve customers; initial notice said Blackbaud was notified by Klue and directed active customers to logged-in FAQ/update material. |
| 72 | Klue Security Incident - Confluent Statement | Confluent Trust Center | Publication date not visible | Newly retained (publication date not visible); retrieved 24-Jul-2026 9:31 PM ET. Direct SafeBase trust-center statement saying Klue was used by Confluent sales and marketing teams, Confluent product-processed customer data was not impacted, Confluent products/platform/infrastructure were not indicated as affected, and copied data was limited to Confluent business information in its CRM system such as business contact and go-to-market opportunity information. |
| 73 | Bulletin: Important Security Notice Regarding Klue | Autodesk Trust Center | June 23, 2026 | Newly retained (>24h); retrieved 28-Jul-2026 9:32 PM ET. Direct Autodesk trust-center advisory stating Klue notified Autodesk on June 16, the incident involved unauthorized access to Klue's third-party integration service and potentially affected Salesforce and Gong integrations, but Autodesk confirmed it does not use the Salesforce or Gong integrations for Klue and identified no direct impact to Autodesk products, services, or systems. |
| 74 | Integrations Restored: Salesforce and Gong Reconnected | Klue | July 27, 2026 | Newly retained (>24h); retrieved 30-Jul-2026 9:32 PM ET. Primary Klue restoration update stating Salesforce and Gong reinstated Klue integrations in their marketplaces, all Klue integrations are available for customers to enable, and Klue added controls including static egress IPs allow-listed by Salesforce and Gong, platform-wide PKCE, tightened OAuth token lifecycle policies, elimination of GitHub personal access tokens, centralized monitoring and detection, runtime network filtering, and deployment-pipeline allowlist controls. |
| 75 | What a Security Incident Taught Us About Securing a Modern SaaS Platform | Klue | July 31, 2026, 6:50 PM ET; modified July 31, 2026, 6:54 PM ET | Freshly reported (<24h); retrieved 31-Jul-2026 9:32 PM ET. Primary Klue CTO post adding a more granular two-phase intrusion narrative, GitHub PAT source-code access and second PAT discovery, unauthorized build/deployment path, stored OAuth-token access, June 12 containment, CrowdStrike no-post-containment-activity finding, and remediation principles for GitHub/CI-CD, default-deny network controls, OAuth token rotation/expiration, IP-range allow-listing, integration least privilege, and distributed incident evidence. |
| 76 | Klue Security Incident | Yext Trust Center | Publication date not visible | Newly retained (publication date not visible); retrieved 02-Aug-2026 9:32 PM ET. Direct SafeBase trust-center notice stating Yext was affected by the Klue incident, the attacker used stolen Klue-held credentials to run read-only queries against Yext's internal Salesforce CRM for roughly 17 hours on June 11-12, exposed business contact details for customers and prospects, and did not access the Yext platform, products, infrastructure, customer content, customer-facing systems, end-user data, payment-card data, Google Workspace, or Slack. |
| 77 | Klue Security Update: What Happened and What Customers Should Know | Commvault Trust Center | July 13, 2026 | Newly retained (>24h); retrieved 03-Aug-2026 9:32 PM ET. Rendered Vanta trust-center notice stating Commvault used Klue, removed the Klue integration, contained unauthorized access, and determined accessed data was limited to business relationship and sales activity information in Commvault's Salesforce environment, including business contact information, internal account information, sales opportunities, and partner status, while stating no customer data, Commvault solutions or services, customer backup data, product metadata, or logs were affected. |
| 78 | The NetDocuments Service Not Impacted by Klue Security Incident | NetDocuments TrustShare | June 26, 2026, 3:20 PM ET | Newly retained (>24h); retrieved 03-Aug-2026 9:32 PM ET. Rendered TrustShare customer advisory stating NetDocuments uses Klue with Gong, Salesforce, Slack, and Microsoft Teams integrations, reviewed the Klue-provided log package, and determined impact was limited to a list of internal staff who are Gong users, while stating no customer data, prospective customer data, or Customer Repository Data was accessed or compromised and the NetDocuments Service was not impacted. |
| 79 | Notice of Data Breach | Neon One | July 31, 2026 | Newly retained (>24h); retrieved 04-Aug-2026 9:31 PM ET from the Nebraska Attorney General data-breach document store. Direct public notice letter stating Neon One became aware on 16-Jun-2026 of a Klue cybersecurity incident involving an integration service for Neon One's Salesforce customer relationship management software, resulting in unauthorized access to some personal information between 11-Jun-2026 and 12-Jun-2026, with the incident contained and no further impact identified. |
| 80 | 2026-1291 - Betterment | Massachusetts Attorney General Data Breach Notification Portal / Betterment | August 5, 2026 | Newly retained (>24h); retrieved 10-Aug-2026 9:36 PM ET; PDF text re-reviewed 11-Aug-2026 9:30 PM ET. Regulator-hosted public notice letter stating Klue Labs Inc., a vendor used by Betterment's sales team, had access to a Salesforce database containing Betterment data, that unauthorized access involved a file containing name and Social Security number, that Betterment's computer systems were not accessed, and that Betterment offered two years of Kroll identity monitoring. |
Expansion Research Sources
These sources add the Salesloft Drift comparator: a prior Salesforce OAuth supply-chain campaign where a trusted SaaS integration and stolen OAuth tokens created downstream Salesforce exposure. AI Monitoring Agent additions are retained in the baseline set when they directly update the Klue event, customer notices, follow-on extortion posture, or Salesforce response guidance.
| # | Source | Publisher | Published | Why Used |
|---|---|---|---|---|
| 18 | Widespread Data Theft Targets Salesforce Instances via Salesloft Drift | Google Cloud / GTIG | August 26, 2025 | Expansion research comparator: authoritative threat-intelligence reporting on UNC6395, compromised Salesloft Drift OAuth tokens, Salesforce data theft, Drift Email scope expansion, and token/credential response actions. |
| 19 | Salesloft breached to steal OAuth tokens for Salesforce data-theft attacks | BleepingComputer | August 26, 2025 | Expansion research comparator explaining Salesloft Drift, why OAuth/refresh tokens created downstream Salesforce exposure, and how the earlier Drift incident resembles the Klue supply-chain pattern. |
| 20 | Widespread Salesforce Data Theft via Compromised Salesloft Drift OAuth Tokens | Arctic Wolf | August 27, 2025 | Expansion research on Drift/Salesforce campaign details, no-Salesforce-platform-compromise caveat, impacted-customer outreach, and reauthentication guidance. |
| 21 | Threat Brief: Salesloft Drift Integration Used To Compromise Salesforce Instances | Unit 42 | September 2, 2025 | Expansion research on mass Salesforce data exfiltration, affected objects, credential/secret hunting, anti-forensics through query-job deletion, and hunting guidance. |
| 22 | Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Platforms | FBI / IC3 | September 12, 2025 | Government expansion source tying UNC6395 to compromised Salesloft Drift OAuth tokens, Salesforce data theft, extortion risk, and public indicators/tactics. |
| 23 | Drift App (Salesloft) Unauthorized Access Incident | Salesforce Help | May 4, 2026 | Official Salesforce reference for the Drift app unauthorized-access incident, used to separate the May 2026 publication/update date from the August 2025 campaign window. |
| 24 | Cybersecurity Alert - Salesloft Drift AI Supply Chain Attack | FINRA | September 2025 | Sector-facing expansion source explaining more than 700 impacted organizations, UNC6395/GRUB1 attribution, stolen OAuth authentication tokens, and downstream Salesforce/Google Workspace/Slack implications. |
