Klue breach lead to Salesforce data theft, Huntress affected
2026-06-19T20:51:46Z•bd68cab71c103f2e085474984c77c2c11d131bdf12bb653d1245371a4948d06b
CVE-2026-20253cisa-kevcredential-compromisecrypto-stealerdata-theftgithublog-managementmalwarepatchingsalesforcesplunksupply-chainthird-party-integrationsunauthenticated-rcevirustotalyoutube
What happened
Multiple security stories: A breach at market intelligence platform Klue led to credential compromise that cascaded into customer data theft (including Salesforce) affecting vendors such as Huntress — illustrating risks from third‑party integrations and credential reuse. A crypto‑stealer campaign abused social proof on GitHub, YouTube and VirusTotal to distribute malicious trading/gambling tools. Critically, CISA added CVE-2026-20253 — an unauthenticated RCE in Splunk Enterprise — to its Known Exploited Vulnerabilities list with confirmed in‑the‑wild exploitation; organizations are urged to or
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- bd68cab71c103f2e085474984c77c2c11d131bdf12bb653d1245371a4948d06b
- Enrichment time
- 2026-06-19T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.