Home / Security updates / Klue Security Incident
Klue Security Incident
Security updates detail rendered from /security-updates/upd_26ef1c698dd901d0.
Overview
| ID | upd_26ef1c698dd901d0 |
| Collection | Security Updates |
| Provider | SafeBase |
| Company | Automox |
| URL | - |
| Counts | - |
| Updated | - |
Raw record
| Field | Value |
|---|---|
| id | upd_26ef1c698dd901d0 |
| providerId | safebase |
| organizationId | org_5dc0d6ce75d1bd33 |
| trustCenterId | tc_ae5c8a1c01c12438 |
| title | Klue Security Incident |
| message | Automox uses Klue, a competitive intelligence platform integrated with our Salesforce environment. Following Klue's disclosure of a security incident in which the extortion group Icarus used a compromised Klue credential to steal OAuth tokens and access connected customers' Salesforce environments, the Automox security team investigated any potential impact to our environment and data. We found no indicators of compromise in our internal logs. As an additional measure, we validated directly within Salesforce by reviewing Login History and Connected App OAuth usage for the Klue application, opened a support case with Salesforce, and rotated and revoked the Klue integration's credentials as a precaution. With Klue's cooperation, we reviewed the full set of Salesforce logs for the integration, covering all API event types across the period of exposure, and cross-referenced that activity against Icarus's known malicious IP addresses and Klue's own flagged egress addresses. We found no ano |
| url | - |
| publishedAt | 2026-06-29 |
| source | {
"field": "statuspage/public/compliance-update",
"category": "incidents"
} |
| company | {
"id": "org_5dc0d6ce75d1bd33",
"name": "Automox",
"domains": [
"security.automox.com",
"automox.com"
]
} |
| trust_center | {
"id": "tc_ae5c8a1c01c12438",
"name": "Automox",
"url": "https://security.automox.com",
"host": "security.automox.com"
} |
| provider | {
"id": "safebase",
"name": "SafeBase"
} |
| links | {
"self": "/v1/security-updates/upd_26ef1c698dd901d0",
"company": "/v1/companies/org_5dc0d6ce75d1bd33",
"trust_center": "/v1/trust-centers/tc_ae5c8a1c01c12438",
"provider": "/v1/providers/safebase"
} |
Get this page with API
Rendered from the bluedoor Trust Centers API. Reproduce it:
GET https://api.bluedoor.sh/trust-centers/v1/security-updates/upd_26ef1c698dd901d0JSON