Skip to main content
TaniumCybersecurity incident

Tanium was one of at least 10 organizations that confirmed its Salesforce data was exfiltrated in the June 2026 supply chain attack originating from the compromised Klue integration.

What happened

Post: "Should you trust AI agents with access to your CRM?"

Source

RedditSep 15, 2026By u/Liana_Preston

r/hubspot

Should you trust AI agents with access to your CRM?

upvotes
2
comments
6

Post

Cybersecurity has changed. Attackers no longer write code that follows a fixed script. If the script hits a defence it was not programmed to crack, it fails. Security teams built their defences around known patterns and could usually stay ahead. Those days are over. In June 2026, researchers at the University of Toronto built an AI-powered worm that changes the game. It uses open-weight AI models to analyze each system it infects, decide which vulnerabilities to exploit next and adapt its strategy in real time. In a controlled experiment on a 33-host network, the worm identified an average of 31.3 vulnerabilities and gained elevated access on roughly three-quarters of the hosts it actively targeted. It spread to 62 % of the network over 7 days, with no knowledge of the network and no human guidance. Now connect that to what happened to Salesforce just weeks later. On June 11, attackers compromised Klue, a competitive intelligence platform that integrates with Salesforce. They used a long-disused but still active testing credential to insert malicious code into Klue's backend. The code stole OAuth tokens that Klue used to connect to its customers' Salesforce environments. With those tokens, the attackers bypassed multi-factor authentication and used an automated Python script through the Salesforce REST API to extract large volumes of data. Nearly 1,000 data requests were...

Keep reading with a free account

The rest of this post, and every signal for Tanium, is in your free account.

Extracted from these lines

  • At least 10 organizations confirmed their Salesforce data had been copied, including Huntress, HackerOne, Snyk, Recorded Future, Tanium, Jamf, Gong, OneTrust, and Sprout Social.

    From the post

  • The attackers did not breach Salesforce. They stole the keys that a trusted integration used to access Salesforce and then used that access exactly as it was designed to be used.

    From the post

Comments on the post

5 of 6 comments
  • “I think there’s a middle ground between “agents should never act autonomously” and giving them unrestricted access. The bigger issue is whether the agent is also responsible for deciding what is safe or correct. For high-impact CRM actions, I’d rather have a deterministic layer make that decision based on actual CRM data and explicit rules, then let the agent act on the result. That’s the ap”

    u/TrueTax9754 points · Sep 15, 2026View

  • “I have several routines that update deals, tickets, my jira. They run weekly and do stuff I would forget”

    u/Poat5401 points · Sep 15, 2026View

  • “CRM access should be capability based, not an all-or-nothing trust decision. Give the agent read access only to required objects, restrict writes to specific fields, and route deletes, exports, ownership changes, and bulk updates through approval. Agentix Labs is relevant because safe automation depends on coupling agent reasoning with narrow permissions and policy checks. Use a dedicated service”

    u/Otherwise_Wave93741 points · Sep 15, 2026View

  • “The data side is easy to overlook too...an agent can follow every permission rule and still act on an invalid or outdated email. thats where email verification befoe CRM automation can help alongside the approval contrls you mentioned.”

    u/Glass_Honeydew42801 points · Sep 15, 2026View

  • “We've been looking at this less as an "AI or no AI" question and more as a permissions problem. An agent having CRM access doesn't necessarily mean it should have unrestricted write or export access. For sensitive actions, approval gates, limited permissions, and a clear audit trail become pretty important. The agent can handle the repetitive work without being the final authority.”

    u/Growth_Natives1 points · Sep 17, 2026View

Extracted by Autobound

From the Signal API record
Signal
Cybersecurity incident

What this signalsUser posts often show product pain before it reaches reviews or churn.

Subreddit
r/hubspot
Stage
Confirmed
Event date
Jun 2026

Companies

  • KlueAlso named
  • SalesforceAlso named

The full record

From the Signal API record

Numbers

Mentions
1

Details

Timing
Completed
Category
Breach
Virality
Low
Post kind
Text
Prominence
Core
Company's role
Subject
Signal category
Event

Topics and mentions

Topics

  • cybersecurity
  • data breach
  • supply chain attack

Products named

  • Salesforce

Extraction

Sentiment
Negative
Detected
Sep 15, 2026
signal_type
reddit-company
signal_subtype
cybersecurityIncident

Use this data

Get every Reddit signal for Tanium and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Tanium this week?”

  2. Send it to your own tools

    The Signal API returns Reddit signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full reddit-company record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/543b8434-dbbf-5558-a85c-13c3490c1b77 returns this record as JSON. POST /v1/companies/enrich returns every signal for tanium.com.

{
  "signal_id": "543b8434-dbbf-5558-a85c-13c3490c1b77",
  "signal_type": "reddit-company",
  "signal_subtype": "cybersecurityIncident",
  "detected_at": "2026-09-15T14:42:06+00:00",
  "company": {
    "name": "Tanium",
    "domain": "tanium.com"
  },
  "data": {
    "nsfw": false,
    "stage": "confirmed",
    "awards": 0,
    "timing": "completed",
    "topics": [
      "cybersecurity",
      "data breach",
      "supply chain attack"
    ],
    "post_id": "1wh2b6t",
    "summary": "Tanium was one of at least 10 organizations that confirmed its Salesforce data was exfiltrated in the June 2026 supply chain attack originating from the compromised Klue integration.",
    "category": "breach",
    "comments": [
      {
        "url": "https://www.reddit.com/r/hubspot/comments/1wh2b6t/comment/p9zsi3b/",
        "depth": 0,
        "score": 4,
        "author": "TrueTax975",
        "excerpt": "I think there’s a middle ground between “agents should never act autonomously” and giving them unrestricted access.\n\n The bigger issue is whether the agent is also responsible for deciding what is safe or correct.\n\n For high-impact CRM actions, I’d rather have a deterministic layer make that decision based on actual CRM data and explicit rules, then let the agent act on the result.\n\n That’s the ap",
        "posted_at": "2026-09-15T17:08:08.000Z",
        "author_url": "https://www.reddit.com/user/TrueTax975/"
      },
      {
        "url": "https://www.reddit.com/r/hubspot/comments/1wh2b6t/comment/p9z553a/",
        "depth": 0,
        "score": 1,
        "author": "Poat540",
        "excerpt": "I have several routines that update deals, tickets, my jira. They run weekly and do stuff I would forget",
        "posted_at": "2026-09-15T15:30:56.000Z",
        "author_url": "https://www.reddit.com/user/Poat540/"
      },
      {
        "url": "https://www.reddit.com/r/hubspot/comments/1wh2b6t/comment/p9zq7ad/",
        "depth": 0,
        "score": 1,
        "author": "Otherwise_Wave9374",
        "excerpt": "CRM access should be capability based, not an all-or-nothing trust decision. Give the agent read access only to required objects, restrict writes to specific fields, and route deletes, exports, ownership changes, and bulk updates through approval. Agentix Labs is relevant because safe automation depends on coupling agent reasoning with narrow permissions and policy checks. Use a dedicated service",
        "posted_at": "2026-09-15T16:58:33.000Z",
        "author_url": "https://www.reddit.com/user/Otherwise_Wave9374/"
      },
      {
        "url": "https://www.reddit.com/r/hubspot/comments/1wh2b6t/comment/pa0c2cv/",
        "depth": 0,
        "score": 1,
        "author": "Glass_Honeydew4280",
        "excerpt": "The data side is easy to overlook too...an agent can follow every permission rule and still act on an invalid or outdated email. thats where email verification befoe CRM automation can help alongside the approval contrls you mentioned.",
        "posted_at": "2026-09-15T18:29:22.000Z",
        "author_url": "https://www.reddit.com/user/Glass_Honeydew4280/"
      },
      {
        "url": "https://www.reddit.com/r/hubspot/comments/1wh2b6t/comment/pabpeu4/",
        "depth": 0,
        "score": 1,
        "author": "Growth_Natives",
        "excerpt": "We've been looking at this less as an \"AI or no AI\" question and more as a permissions problem. An agent having CRM access doesn't necessarily mean it should have unrestricted write or export access. For sensitive actions, approval gates, limited permissions, and a clear audit trail become pretty important. The agent can handle the repetitive work without being the final authority.",
        "posted_at": "2026-09-17T07:32:46.000Z",
        "author_url": "https://www.reddit.com/user/Growth_Natives/"
      },
      {
        "url": "https://www.reddit.com/r/hubspot/comments/1wh2b6t/comment/pad7t8s/",
        "depth": 0,
        "score": 1,
        "author": "hubs_dev",
        "excerpt": "I think posts this long should be banned immediately... tldr sorry",
        "posted_at": "2026-09-17T13:36:06.000Z",
        "author_url": "https://www.reddit.com/user/hubs_dev/"
      }
    ],
    "evidence": [
      "[post] At least 10 organizations confirmed their Salesforce data had been copied, including Huntress, HackerOne, Snyk, Recorded Future, Tanium, Jamf, Gong, OneTrust, and Sprout Social.",
      "[post] The attackers did not breach Salesforce. They stole the keys that a trusted integration used to access Salesforce and then used that access exactly as it was designed to be used."
    ],
    "virality": "low",
    "post_date": "2026-09-15T14:42:06.000Z",
    "post_kind": "text",
    "post_text": "Cybersecurity has changed. Attackers no longer write code that follows a fixed script. If the script hits a defence it was not programmed to crack, it fails. Security teams built their defences around known patterns and could usually stay ahead. Those days are over.\n\nIn June 2026, researchers at the University of Toronto built an AI-powered worm that changes the game. It uses open-weight AI models to analyze each system it infects, decide which vulnerabilities to exploit next and adapt its strategy in real time. In a controlled experiment on a 33-host network, the worm identified an average of 31.3 vulnerabilities and gained elevated access on roughly three-quarters of the hosts it actively targeted. It spread to 62 % of the network over 7 days, with no knowledge of the network and no human guidance.\n\nNow connect that to what happened to Salesforce just weeks later. On June 11, attackers compromised Klue, a competitive intelligence platform that integrates with Salesforce. They used a long-disused but still active testing credential to insert malicious code into Klue's backend. The code stole OAuth tokens that Klue used to connect to its customers' Salesforce environments. With those tokens, the attackers bypassed multi-factor authentication and used an automated Python script through the Salesforce REST API to extract large volumes of data. Nearly 1,000 data requests were...",
    "sentiment": "negative",
    "subreddit": "hubspot",
    "event_date": "2026-06",
    "post_title": "Should you trust AI agents with access to your CRM?",
    "prominence": "core",
    "source_url": "https://www.reddit.com/r/hubspot/comments/1wh2b6t/should_you_trust_ai_agents_with_access_to_your_crm/",
    "entity_role": "subject",
    "post_author": "Liana_Preston",
    "upvote_ratio": 1,
    "mention_count": 1,
    "mention_surge": false,
    "subreddit_url": "https://www.reddit.com/r/hubspot/",
    "total_upvotes": 2,
    "comments_total": 6,
    "total_comments": 6,
    "event_date_text": "June 2026",
    "other_companies": [
      {
        "name": "Klue",
        "role": "partner",
        "domain": "klue.com"
      },
      {
        "name": "Salesforce",
        "role": "partner"
      }
    ],
    "post_author_url": "https://www.reddit.com/user/Liana_Preston/",
    "signal_category": "event",
    "comments_included": 6,
    "products_mentioned": [
      "Salesforce"
    ]
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.