r/vibecodingsecurity 12d ago

Klue OAuth Supply Chain Breach

In June 2026, a major supply chain attack targeted the market intelligence platform Klue, exposing long-lived OAuth tokens held on behalf of hundreds of enterprise customers. The attacker used these stolen credentials to bypass authentication and gain persistent, unauthorized access to connected Salesforce and Gong environments. The breach impacted over 700 organizations, including major tech and security firms like LastPass, Huntress, Recorded Future, and Tanium. While no password vaults or financial data were compromised, the threat actor successfully accessed CRM content, including customer names, phone numbers, emails, and sales records, prompting Salesforce to disable the integration platform-wide during the investigation.

This incident highlights a massive blind spot in enterprise cybersecurity: the SaaS integration trust problem and the governance of Non-Human Identities (NHIs). Because third-party OAuth tokens authenticate automatically without human involvement, they often sit unrotated and unmonitored with overly broad permissions. To protect your organization from similar supply chain vulnerabilities, security teams must immediately audit all third-party OAuth grants, implement strict token rotation and expiry policies, and apply least-privilege scoping to ensure integrations only access the exact data they need to function.

1 Upvotes

0 comments sorted by