Klue disclosed that hackers exploited a credential left active since 2022 to breach customer data systems. The company failed to revoke the access key after completing a limited pilot program.
The credential, which should have been deactivated after its pilot use ended, provided attackers with access to a system containing encryption keys for customer data. Klue has not explained why the credential remained active for over a year.
The breach affected multiple customers, though Klue has not disclosed the full scope of compromised data or the number of affected users.
The incident highlights a common security gap: credential management across organizations. Access keys from short-term projects or tests often persist longer than intended, creating entry points for attackers.
Klue has not disclosed when the breach was discovered or how long attackers had access to the systems. The company has not yet detailed remediation steps or customer notifications beyond the initial disclosure.
This follows a pattern of breaches stemming from forgotten or mismanaged legacy credentials that organizations fail to audit regularly.
Framework's customer database was compromised in a data breach, though payment information was not exposed. The company has disclosed the incident to affected users.
Security researchers have identified potential hardware backdoors in certain x86 processors. The findings, detailed in a GitHub repository called Rosenbridge, reveal vulnerabilities at the processor level that could allow unauthorized access.
Flock Safety, the traffic camera company, is expanding beyond law enforcement with plans to deploy dashcams in rideshare vehicles and offer coaching services to police departments.
A sharp rise in explicit deepfake images of UK children has been reported by an online safety service, as authorities warn that AI tools are making the creation of sexualized or 'nudified' content increasingly accessible.