The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/AI & Data/ShadowTalk: Powered by ReliaQuest
ShadowTalk: Powered by ReliaQuest artwork

Klue, Kali365, OAuth: When the Front Door Is a Trusted Integration

ShadowTalk: Powered by ReliaQuest · 2026-06-24 · 28 min

0:00--:--

Episode notes

In the Klue compromises threat actors walked in through a trusted integration, using legitimate credentials to quietly siphon Salesforce CRM data at scale. The challenge isn't just responding to Klue. It's recognizing that every OAuth-connected integration in your environment is part of your attack surface. Join hosts Alexandra and John as they discuss: How compromised Klue integrations were leveraged to exfiltrate Salesforce CRM data Attribution and what it signals about the evolving data extortion landscape How Oauth token and device code theft is growing Two questions your organization should be asking right now: How many third-party integrations in your environment have active OAuth access to platforms holding critical data - and when were they last audited? Do you have detections in place for unusual Salesforce API query volume and service account behavior that could signal an active exfiltration? Resources: John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.

More from ShadowTalk: Powered by ReliaQuest

All episodes →
  • How Hackers Are Using AI Right Now: Faster Attacks, Smarter Malware, and a New Arms Race73 / 100
  • ShinyHunters' Expanding Toolkit: Oracle PeopleSoft Zero-Day Exploitation and the BreachForums Defense Gaps
  • China-Linked Cyber Espionage: How OP-512 Exploited Legacy IIS Servers and Evaded Detection
  • SonicWall, MFA Bypass, IABs: Why Patched Devices Are Still Handing Attackers Initial Access
  • Device Code, OAuth, PhaaS: How Session Token Theft is Breaking the Phishing Playbook
Explore the best B2B AI & Data podcasts →
All ShadowTalk: Powered by ReliaQuest episodes →