Klue Breach Exposed Salesforce Data Through Stolen OAuth Tokens
A forgotten Klue credential led to customer OAuth token theft and direct access to Salesforce CRM data across several companies.
Reader edition
A forgotten Klue credential led to customer OAuth token theft and direct access to Salesforce CRM data across several companies.
Island found more than 800 fake skills and MCP servers using credible READMEs and ZIP files to turn capability searches into malware installs.
Five poisoned releases avoided install hooks, launching a detached Node.js process when developer or CI tooling loaded the affected module.
Trend Micro found a Russian-speaking actor using Gemini CLI to rebuild command-and-control infrastructure and operate eight infected computers.
Cursor 3.0 fixed path-handling failures that let injected instructions write beyond a project and tamper with the sandbox protecting the host.
A routine page fetch in older Kiro builds could end with attacker-controlled code running through a rewritten MCP configuration.
The botnet gives AI workbenches priority in its scan queue, then searches compromised hosts for cloud credentials, service-account tokens, and callable tools.
A paid search ad sent victims through a public page on claude.ai before delivering a fake desktop installer.