Jamf A.I CyberSecurity Scoring
Jamf
Company Information
Website:https://www.jamf.com/
Employees number:2,530
Number of followers:124,907
NAICS:5112
Industry Type:Software Development
Homepage:jamf.com
Jamf Risk Score (AI oriented)
Between 600 and 649
JamfSoftware Development
Updated:
15/07/2026
15/07/2026
631/1000
Poor
Caa
Jamf Global Score (TPRM)
xxxx
JamfSoftware Development
Score locked

JamfPoor
Current Score
631Caa (POOR)
01000
3 incidents
-44.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
633
JULY 2026
631
JUNE 2026
691
Breach
25 Jun 2026 • Jamf
Klue: Klue Hit by Double Extortion as Second Hacker Group Emerges
Klue Faces Unprecedented Dual Extortion Attack After Data Breach
630
CRITICAL-61
KLU1782428022
Klue Faces Unprecedented Dual Extortion Attack After Data Breach
Vancouver-based market intelligence platform Klue has disclosed a rare and escalating cybersecurity crisis, involving two criminal groups with conflicting extortion demands following a data breach. The incident, first reported by TechCrunch, marks an unusual case of competing threats targeting the same victim highlighting evolving tactics in cyber extortion.
The breach initially involved a hacking group that stole sensitive customer data, including proprietary market research, competitive analysis, and strategic planning materials used by enterprise clients to track rivals. In a surprising turn, the original attackers later claimed they were deleting the stolen files, though Klue’s customers were warned not to assume the threat had passed. Before any relief could set in, a second criminal group emerged, demanding ransom for the same compromised data.
The situation leaves Klue’s enterprise clients including sales and marketing teams at major corporations in limbo, uncertain whether their highly sensitive business intelligence has been destroyed, leaked, or is now in the hands of multiple threat actors. The competitive intelligence sector handles particularly valuable data, such as go-to-market strategies and product roadmaps, which could cause significant damage if exposed.
Security researchers note that while secondary markets for stolen data are not new, the simultaneous, opposing claims from two criminal groups are highly unusual. The first group’s alleged data deletion could be a face-saving exit or genuine reversal, while the second group’s demands suggest they either independently accessed Klue’s systems or acquired the data from the original attackers.
Klue has not disclosed technical details of the breach, the scope of compromised data, or the number of affected customers. The incident underscores the cascading risks of B2B SaaS breaches, where third-party vendors handling critical business intelligence become high-value targets. It also arrives amid growing enterprise concerns over vendor security postures, following high-profile breaches at platforms like Okta and LastPass.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
719
Cyber Attack
22 Jun 2026 • Jamf
iRhythm Technologies, Jamf, ShapedPlugin, Tanium, Fortinet, Microsoft and Texas Parks and Wildlife Department: 22nd June – Threat Intelligence Report
Cybersecurity Roundup: Major Breaches, AI Exploits, and Critical Vulnerabilities (Week of June 22)
691
CRITICAL-28
FORSHATANMICJAMIRHTEX1782147825
Cybersecurity Roundup: Major Breaches, AI Exploits, and Critical Vulnerabilities (Week of June 22)
This week’s cybersecurity landscape saw significant breaches, supply chain attacks, and emerging AI-driven threats, alongside critical vulnerabilities under active exploitation.
### Major Breaches & Attacks
- Texas Parks and Wildlife Department suffered a third-party breach via its license system vendor, exposing driver’s license details, passport numbers, emails, phone numbers, and addresses of 3.1 million hunting and fishing license customers. Social Security numbers and payment data remained unaffected.
- ShapedPlugin, a WordPress plugin vendor, fell victim to a supply chain attack, delivering malicious updates for three paid plugins. The malware installed a hidden fake WooCommerce plugin to steal admin credentials, database access, and 2FA details, while modifying affected sites. The compromise stemmed from the vendor’s release infrastructure.
- iRhythm Technologies, a U.S. digital health firm specializing in remote cardiac monitoring, confirmed a cyberattack where threat actors via a social engineering breach of third-party business applications stole protected health information, proprietary data, and personal records. Clinical systems were not impacted.
- Klue, a market intelligence platform, disclosed a breach after attackers used compromised legacy integration credentials to steal OAuth tokens linked to customer Salesforce environments. The tokens enabled the theft of sales and customer data from clients, including Huntress, Recorded Future, Tanium, and Jamf. The Icarus extortion group claimed responsibility.
### AI-Driven Threats
- Microsoft researchers uncovered AutoJack, an exploit chain where malicious web pages turn AI browsing agents into remote code execution vectors by abusing localhost trust, missing authentication, and unsafe parameter handling in AutoGen Studio’s MCP WebSocket interface.
- SearchLeak, a prompt injection technique in Microsoft 365 Copilot Search, was revealed to exfiltrate data including emails, authentication codes, and OneDrive/SharePoint files via crafted links abusing Bing image fetches. Microsoft patched the flaw as CVE-2026-42824.
- Researchers analyzed OpenClaw AI agent flaws, demonstrating how hidden contacts and phishing emails could trigger prompt injections, code execution, and data leaks, exposing local tools, secrets, and enterprise data through trusted external interactions.
### Critical Vulnerabilities & Exploits
- Fortinet FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) are being exploited via unauthenticated API requests, enabling path traversal and root-level command execution, risking sandbox takeover and disruption of malware analysis and security workflows.
- Microsoft confirmed CVE-2026-50656, a Defender zero-day allowing privilege escalation to SYSTEM via a race condition. A public proof-of-concept works on fully updated Windows 10 and 11, with a patch in development.
- Cisco acknowledged active exploitation of CVE-2026-20262, an arbitrary file write flaw in Catalyst SD-WAN Manager. Authenticated attackers can overwrite system files and escalate to root, prompting patches for affected devices.
- Splunk Enterprise’s CVE-2026-20253 is under active exploitation, allowing unauthenticated attackers to trigger file operations, potentially leading to remote code execution. Splunk confirmed limited attacks and released security updates.
### Threat Intelligence Highlights
- A crypto clipboard hijacker, written in Rust and targeting Windows and macOS, was distributed via phishing sites and amplified on GitHub, SourceForge, YouTube, and legitimate news platforms. The malware swaps copied wallet addresses to redirect funds to attacker-controlled wallets.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
718
APRIL 2026
717
MARCH 2026
716
FEBRUARY 2026
715
JANUARY 2026
714
DECEMBER 2025
713
NOVEMBER 2025
712
OCTOBER 2025
711
SEPTEMBER 2025
710
JUNE 2025
765
Breach
12 Jun 2025 • Jamf
LastPass, BeyondTrust, Klue, HackerOne, Jamf, Recorded Future, Snyk, Huntress and Tanium: Klue Data Breach 2026: 200 Firms Hit via Old Credential
Klue Breach Exposes 200 Firms via Forgotten 4-Year-Old Credential
706
CRITICAL-59
JAMHUNSNYRECHACLASTANKLUBEY1784126732
Klue Breach Exposes 200 Firms via Forgotten 4-Year-Old Credential
In June 2025, a dormant credential issued by competitive-intelligence platform Klue in 2022 became the entry point for a breach affecting nearly 200 companies, including prominent cybersecurity vendors. The attack, claimed by the extortion group Icarus, exploited an unmonitored OAuth token to access Salesforce environments, underscoring the risks of neglected third-party integrations.
### What Happened?
On June 12, 2025, attackers used a compromised legacy credential originally created for a "limited pilot" to infiltrate Klue’s systems. The credential, left active for four years, granted access to OAuth tokens that Klue used to pull data from connected Salesforce instances. Once inside, the threat actors automated data exfiltration from 195–200 companies, including LastPass, BeyondTrust, Jamf, HackerOne, Recorded Future, Snyk, Tanium, and Huntress.
Klue publicly disclosed the breach on June 15, 2025, confirming data theft from an unspecified number of customers. By late June, affected firms began acknowledging the incident, with LastPass and BeyondTrust clarifying that only business contact and CRM data not core product systems were exposed.
### How the Attack Unfolded
The breach required no zero-day exploits or sophisticated malware just an overlooked credential. The attackers leveraged Klue’s OAuth tokens to access Salesforce environments en masse, demonstrating the dangers of fourth-party risk: a vendor’s vendor (Klue) becoming the weak link in a supply chain.
### Key Victims & Impact
While Klue serves sales and marketing teams, its customer base included security vendors, amplifying the breach’s irony. Confirmed victims span:
- Password management (LastPass)
- Privileged access (BeyondTrust)
- Endpoint security (Tanium, Jamf)
- Threat intelligence (Recorded Future)
- Bug bounty coordination (HackerOne)
- Application security (Snyk)
Huntress reported receiving a ransom note from the attackers via a compromised Australian email address, highlighting the group’s reliance on reused infrastructure.
### Broader Context: A Year of Supply Chain Attacks
The Klue breach coincided with a separate 2026 supply chain campaign targeting open-source security tools, including Trivy, Bitwarden, and Checkmarx. While unrelated, both incidents reflect a trend: attackers increasingly compromise trusted platforms to bypass direct defenses.
### Regulatory & Industry Reactions
- Cyber insurers are tightening scrutiny of third-party integrations, particularly OAuth token hygiene.
- Security vendors on the victim list face heightened procurement questions from enterprise buyers.
- Regulators are paying closer attention to software supply chain risks, though the Klue breach limited to business data may not trigger major notifications.
### Lessons from the Breach
The incident mirrors the 2025 Salesloft Drift breach, where stolen OAuth tokens compromised 700+ Salesforce environments. Both cases reveal a critical gap: point-in-time vendor assessments fail to catch dormant credentials. Mitigation requires:
- Automated expiration for pilot credentials.
- Minimum-scoped OAuth grants (avoiding broad CRM access).
- Recurring token audits to identify stale integrations.
As of June 2026, only ~15 of the estimated 200 affected firms have publicly confirmed exposure, with more expected to disclose as investigations continue. The breach serves as a stark reminder that identity and credential management not just perimeter defenses are central to modern cybersecurity.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Jamf ??
What was Jamf's A.I Rankiteo Cyber Score in July 2026 ??
What was Jamf's A.I Rankiteo Cyber Score in June 2026 ??
What was Jamf's A.I Rankiteo Cyber Score in May 2026 ??
What was Jamf's A.I Rankiteo Cyber Score in April 2026 ??
What was Jamf's A.I Rankiteo Cyber Score in March 2026 ??
What was Jamf's A.I Rankiteo Cyber Score in February 2026 ??
What was Jamf's A.I Rankiteo Cyber Score in January 2026 ??
What was Jamf's A.I Rankiteo Cyber Score in December 2025 ??
What was Jamf's A.I Rankiteo Cyber Score in November 2025 ??
What was Jamf's A.I Rankiteo Cyber Score in October 2025 ??
What was Jamf's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Jamf's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Jamf ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Jamf's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?