LastPass customer data was accessed via a supply chain attack on the Klue market intelligence platform, where attackers used compromised OAuth tokens to breach LastPass's Salesforce environment. The article does not provide a CVSS score, specific affected or fixed software versions, or a recommended workaround.
LastPass disclosed that attackers used OAuth tokens compromised in a supply chain attack on Klue, a market intelligence platform that integrates with CRM and sales tools across organizations, to access customer data stored in its Salesforce environment. βOn June 12th LastPass was made aware of an incident that occurred at Klue (klue.com), a third-party market intelligence platform utilized by our go-to-market teams which integrates with our Salesforce and Gong systems,β LastPass said. βWe immediately launched β¦ More β The post LastPass customer data exposed through Klue supply chain attack appeared first on Help Net Security .