Home / Sep 26, 2026 / Story
0
#7 SecurityWeek general September 25, 2026 at 09:27 UTC

‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration

By Ionut Arghire

AI Summary

Researchers disclosed 'SalesBleed,' three vulnerabilities in Salesforce Agentforce that enabled zero-click data exfiltration by hijacking trusted AI agents to steal data and conduct phishing attacks via Slack. The attack chain abused prompt injection through external web content to smuggle malicious instructions across app boundaries into trusted internal communications channels. Organizations deploying Salesforce Agentforce or similar agentic AI platforms should audit agent permissions and input sanitization controls immediately.

Relevance score: 78.0/100

# More from September 26