r/hubspot
Should you trust AI agents with access to your CRM?
- upvotes
- 2
- comments
- 6
Post
Cybersecurity has changed. Attackers no longer write code that follows a fixed script. If the script hits a defence it was not programmed to crack, it fails. Security teams built their defences around known patterns and could usually stay ahead. Those days are over. In June 2026, researchers at the University of Toronto built an AI-powered worm that changes the game. It uses open-weight AI models to analyze each system it infects, decide which vulnerabilities to exploit next and adapt its strategy in real time. In a controlled experiment on a 33-host network, the worm identified an average of 31.3 vulnerabilities and gained elevated access on roughly three-quarters of the hosts it actively targeted. It spread to 62 % of the network over 7 days, with no knowledge of the network and no human guidance. Now connect that to what happened to Salesforce just weeks later. On June 11, attackers compromised Klue, a competitive intelligence platform that integrates with Salesforce. They used a long-disused but still active testing credential to insert malicious code into Klue's backend. The code stole OAuth tokens that Klue used to connect to its customers' Salesforce environments. With those tokens, the attackers bypassed multi-factor authentication and used an automated Python script through the Salesforce REST API to extract large volumes of data. Nearly 1,000 data requests were...
Keep reading with a free account
The rest of this post, and every signal for OneTrust, is in your free account.
Extracted from these lines
At least 10 organizations confirmed their Salesforce data had been copied, including Huntress, HackerOne, Snyk, Recorded Future, Tanium, Jamf, Gong, OneTrust, and Sprout Social.
From the post
The attackers did not breach Salesforce. They stole the keys that a trusted integration used to access Salesforce and then used that access exactly as it was designed to be used.
From the post