#7
SecurityWeek
general
September 25, 2026 at 09:27 UTC
‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
By Ionut Arghire
AI Summary
Researchers disclosed 'SalesBleed,' three vulnerabilities in Salesforce Agentforce that enabled zero-click data exfiltration by hijacking trusted AI agents to steal data and conduct phishing attacks via Slack. The attack chain abused prompt injection through external web content to smuggle malicious instructions across app boundaries into trusted internal communications channels. Organizations deploying Salesforce Agentforce or similar agentic AI platforms should audit agent permissions and input sanitization controls immediately.
Relevance score: 78.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →