Klue OAuth breach victim list grows as Icarus hackers claim attack
2026-06-20T07:23:26Z•44716fc08a6493e8a363fd7b45ef7cb796751e8bee3cc0efed8897835c693cf2
AI-agent identityCISA advisoryEDR evasionEvil CorpFortiBleedFortinetGentlemen RaaSGravity SMTPIcarus extortionMFA bypassOAuth breachPII exposureRansomwareSalesforce data theftSocGholishSplunk EnterpriseTexas data breachUSB wormWordPress pluginactive exploitationcredential leakcrypto-stealerinformation disclosure
What happened
Multiple high-impact incidents reported: Klue confirmed an OAuth compromise tied to the Icarus group leading to theft of Salesforce tokens/data and ongoing extortion; CISA warned of an actively exploited, critical Splunk Enterprise vulnerability requiring urgent patching; Fortinet credential data ("FortiBleed") was leaked impacting many devices; a Texas vendor breach exposed >3 million driver license records; attackers are exploiting an unauthenticated information-disclosure bug in the Gravity SMTP WordPress plugin (~100k sites); Gentlemen ransomware is deploying multiple EDR-killing methods;,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 44716fc08a6493e8a363fd7b45ef7cb796751e8bee3cc0efed8897835c693cf2
- Enrichment time
- 2026-06-20T07:23:26Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.