Klue OAuth breach victim list grows as Icarus hackers claim attack

2026-06-20T07:23:26Z44716fc08a6493e8a363fd7b45ef7cb796751e8bee3cc0efed8897835c693cf2
AI-agent identityCISA advisoryEDR evasionEvil CorpFortiBleedFortinetGentlemen RaaSGravity SMTPIcarus extortionMFA bypassOAuth breachPII exposureRansomwareSalesforce data theftSocGholishSplunk EnterpriseTexas data breachUSB wormWordPress pluginactive exploitationcredential leakcrypto-stealerinformation disclosure

What happened

Multiple high-impact incidents reported: Klue confirmed an OAuth compromise tied to the Icarus group leading to theft of Salesforce tokens/data and ongoing extortion; CISA warned of an actively exploited, critical Splunk Enterprise vulnerability requiring urgent patching; Fortinet credential data ("FortiBleed") was leaked impacting many devices; a Texas vendor breach exposed >3 million driver license records; attackers are exploiting an unauthenticated information-disclosure bug in the Gravity SMTP WordPress plugin (~100k sites); Gentlemen ransomware is deploying multiple EDR-killing methods;,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
44716fc08a6493e8a363fd7b45ef7cb796751e8bee3cc0efed8897835c693cf2
Enrichment time
2026-06-20T07:23:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Klue OAuth breach victim list grows as Icarus hackers claim attack · Baitaphish