CVE-2026-61699 is a high-severity vulnerability (CVSS 8.1) in nebula-mesh, Slack's self-hosted mesh VPN control plane. Prior to version 0.7.1, the blocklist mechanism fails to reach peer configurations, allowing attackers who exfiltrate host credentials to maintain full network overlay access for 30–365 days after revocation. Operator-visible state (UI and audit logs) does not accurately reflect the compromised host's actual connectivity status. Update to version 0.7.1 or later to remediate.
Slack
Team messaging and collaboration.
Recent threats
Security researchers at Zenity Labs demonstrated an indirect prompt-injection attack chain in Claude in Chrome that enables account takeovers of Slack and other services. The exploit tricks the AI agent into executing arbitrary code within authenticated browser sessions, allowing attackers to intercept email-based verification codes used for Slack account authentication. The vulnerability chain involves malicious email content, package registry manipulation, and automated credential theft.
Slack OAuth tokens were harvested during a Klue platform breach on June 11, 2026. Attackers who compromised Klue's backend injected malicious code that stole OAuth credentials from customers using Klue to integrate with Slack, Salesforce, and other enterprise tools. The extortion-focused threat group Icarus is attributed to the attack. Affected Slack organizations should revoke compromised OAuth tokens and review integration access logs.
- Klue breach lead to Salesforce data theft, Huntress affected - H(opens in a new tab)
- Hackers Breach Klue Integration to Steal Salesforce CRM Data(opens in a new tab)
- Hackers Exploit Klue Integration to Steal Salesforce CRM Data Us(opens in a new tab)
- Cybersecurity Firms Impacted by Klue Supply Chain Attack - Secur(opens in a new tab)
- Klue OAuth Integration Breach Exposes Salesforce Customer Data i(opens in a new tab)
- Risky Bulletin: Klue breach impacts security firms(opens in a new tab)