Scope of Salesforce Attacks Expands as Icarus Leaks Data
2026-06-24T02:51:41Z•37c5adb96b60284c6a66fa3baf0a66888401c291afed4ccaaaade1b7d02afba8
AI privacyCI/CDCordycepsDifyTapFortiBleedFortiGateFortinetHTTP/2 DoSIvantiKlueOAuth token abuseOracle ERPSalesforceSocGholishTDScredential harvestingcredential theftdata breachmalicious pull requestsmalwareransomwaresupply chainthird-party compromisevulnerabilitieszero-day
What happened
Multiple high-impact incidents and trending attack techniques appear across the feed: attackers are abusing third-party application OAuth tokens to steal Salesforce customer data (Klue/Battlecards), while a massive FortiGate-focused campaign (FortiBleed/Fortinet credential harvest) has exfiltrated tens of millions of credentials from hundreds of thousands of devices. Supply-chain and developer workflow attacks are rising (malicious pull requests dubbed 'Cordyceps', leaked GitHub tokens, CI/CD risks), alongside active exploitation of high‑severity bugs and zero‑days (Oracle ERP, Ivanti, others)
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 37c5adb96b60284c6a66fa3baf0a66888401c291afed4ccaaaade1b7d02afba8
- Enrichment time
- 2026-06-24T02:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.