bluedoor data·Trust Centers API·bluedoor.sh

Home / Security updates / Klue Security Incident

Klue Security Incident

Security updates detail rendered from /security-updates/upd_26ef1c698dd901d0.

Overview

IDupd_26ef1c698dd901d0
CollectionSecurity Updates
ProviderSafeBase
CompanyAutomox
URL-
Counts-
Updated-

Raw record

FieldValue
idupd_26ef1c698dd901d0
providerIdsafebase
organizationIdorg_5dc0d6ce75d1bd33
trustCenterIdtc_ae5c8a1c01c12438
titleKlue Security Incident
messageAutomox uses Klue, a competitive intelligence platform integrated with our Salesforce environment. Following Klue's disclosure of a security incident in which the extortion group Icarus used a compromised Klue credential to steal OAuth tokens and access connected customers' Salesforce environments, the Automox security team investigated any potential impact to our environment and data. We found no indicators of compromise in our internal logs. As an additional measure, we validated directly within Salesforce by reviewing Login History and Connected App OAuth usage for the Klue application, opened a support case with Salesforce, and rotated and revoked the Klue integration's credentials as a precaution. With Klue's cooperation, we reviewed the full set of Salesforce logs for the integration, covering all API event types across the period of exposure, and cross-referenced that activity against Icarus's known malicious IP addresses and Klue's own flagged egress addresses. We found no ano
url-
publishedAt2026-06-29
source
{
  "field": "statuspage/public/compliance-update",
  "category": "incidents"
}
company
{
  "id": "org_5dc0d6ce75d1bd33",
  "name": "Automox",
  "domains": [
    "security.automox.com",
    "automox.com"
  ]
}
trust_center
{
  "id": "tc_ae5c8a1c01c12438",
  "name": "Automox",
  "url": "https://security.automox.com",
  "host": "security.automox.com"
}
provider
{
  "id": "safebase",
  "name": "SafeBase"
}
links
{
  "self": "/v1/security-updates/upd_26ef1c698dd901d0",
  "company": "/v1/companies/org_5dc0d6ce75d1bd33",
  "trust_center": "/v1/trust-centers/tc_ae5c8a1c01c12438",
  "provider": "/v1/providers/safebase"
}
Get this page with API

Rendered from the bluedoor Trust Centers API. Reproduce it:

GET https://api.bluedoor.sh/trust-centers/v1/security-updates/upd_26ef1c698dd901d0JSON