Back to news

OAuth Abuse Hits Salesforce-Klue Link; Android Botnet Tied to Israeli Proxy Firm

Two cybersecurity incidents this week expose how trusted integrations and consumer devices can become attack vectors against enterprise data.

OAuth Abuse Hits Salesforce-Klue Link; Android Botnet Tied to Israeli Proxy Firm

What happened

Salesforce pulled the plug on its integration with Klue Battlecards on June 11, 2026, after a security incident at the competitive intelligence platform resulted in OAuth tokens being abused to access customer data. The connection between the two platforms remains suspended pending further investigation, leaving organizations that relied on the integration without access. Separately, researchers from several security firms this week attributed the four-year-old Popa botnet — a large-scale Android-based operation infecting consumer TV boxes — to NetNut, a residential proxy service run by publicly-traded Israeli company Alagene. The botnet has reportedly been used to conduct advertising fraud, credential-based account takeovers, and mass data-scraping campaigns by routing malicious traffic through millions of compromised household devices.

Why it matters for your business

The Klue incident is a sharp reminder that third-party SaaS integrations introduce risk proportional to the access permissions they hold. OAuth tokens, if compromised at a vendor level, can expose sensitive CRM data without any failure on the customer's side — meaning your security posture is only as strong as that of your weakest integrated application. Operations and IT leaders should audit all active OAuth connections in Salesforce and similar platforms, revoke tokens for any application that is dormant or under scrutiny, and demand incident transparency from vendors. The Popa botnet case adds another dimension: even corporate networks can become collateral damage when residential proxies route fraudulent traffic in ways that mimic legitimate user behavior, complicating detection by standard security tools.

What to watch next

Klue and Salesforce have not yet disclosed the full scope of customer data affected, and regulatory notifications under frameworks such as GDPR and CCPA could follow as the investigation matures. For the Popa botnet, the attribution of a criminal infrastructure to a publicly-traded company will likely attract regulatory and legal scrutiny of the residential proxy industry more broadly. Security teams should monitor for any indicators of compromise tied to NetNut-linked IP ranges, particularly if their environments handle high-value authentication or advertising data.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp