Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Israel v Republic of Ireland: Republic of Ireland to wear black armbands for Israel game

    September 27, 2026

    Levoit’s new air purifier is for the pet odors that have taken over your apartment

    September 27, 2026

    ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration

    September 27, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Israel v Republic of Ireland: Republic of Ireland to wear black armbands for Israel game
    • Levoit’s new air purifier is for the pet odors that have taken over your apartment
    • ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
    • Samourai Wallet Co-Founder Recounts 30-Day Prison Transfer
    • Mother of woman found hanging in tree shocked as police say body was staged
    • A Gravitational Battle Within the Earth Is Changing the Length of Days
    • Windows, Linux, Android File Notification Systems Leak User Activity
    • The NFT party is over and everybody now owes storage rent
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, September 27
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 27, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Three vulnerabilities in Salesforce Agentforce could have allowed attackers to hijack trusted agents for sensitive CRM data exfiltration and phishing, Zenity Labs reports.

    Dubbed SalesBleed, the flaws could be exploited via Web-to-Lead forms, Salesforce’s official lead-collection mechanism, which also provides a direct path to the CRM.

    Malicious instructions injected into a Web-to-Lead lead would remain dormant until an employee asks an Agentforce agent to interact with the submission, causing the agent to process the poisoned lead and execute the hidden instructions.

    According to Zenity Labs, two of the SalesBleed bugs could be exploited in zero-click data exfiltration attacks, while the third allowed attackers to weaponize an Agentforce agent to distribute phishing messages.

    The first two flaws were caused by multiple weaknesses in Trusted URLs, the security mechanism designed to block Agentforce from displaying URLs and images from untrusted sources. The third affects the Agentforce-Slack integration.

    Zenity Labs discovered that a Web-to-Lead form payload could be used to access leads and accounts table data and then use HTML image tags for zero-click CRM data exfiltration to the attacker’s server.

    Advertisement. Scroll to continue reading.

    “Agentforce reported that the content had been blocked by the organization’s security policies, even though the sensitive CRM data had already been transmitted to the attacker-controlled server,” the company notes.

    While Trusted URLs should prevent Agentforce from accessing and sending data to unapproved domains, Zenity Labs discovered that the mechanism did not recognize top-level domains and that character sequences could tamper with URL parsing.

    Using the same poisoned Web-to-Lead mechanism, an attacker could interact with the Agentforce agent via Slack, which automatically retrieves link information for previews.

    “Specially constructed links can cause Slack to initiate requests that carry CRM data to attacker-controlled infrastructure as soon as the links appear,” Zenity Labs says.

    Additionally, the cybersecurity firm discovered that Agentforce’s integration with Slack could be abused to turn the AI agents into a social-engineering mechanism and send messages to various internal Slack channels.

    Because the agent did not identify the user sending the message, an attacker could use a malicious Web-to-Lead to hijack the agent and post phishing messages to Slack using the agent’s identity.

    “Employees receive a message from a trusted system already operating inside their workplace rather than from an unfamiliar outside sender. Users who follow the phishing link and surrender their credentials could give attackers access to email, Slack, source code repositories and other enterprise applications available through the compromised identity, Zenity Labs notes.

    The cybersecurity firm reported the SalesBleed vulnerabilities on June 1, and Salesforce confirmed that all three bugs had been addressed by August 19.

    Related: Roundcube Webmail Vulnerability in Attackers’ Crosshairs

    Related: Autonomous AI Hacks Raise Thorny Questions of Legal Accountability

    Related: AI-Powered Campaign Targets Hundreds of Online Retailers

    Related: SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted

    Agentforce data Enabled Exfiltration flaws SalesBleed Salesforce zeroclick
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Windows, Linux, Android File Notification Systems Leak User Activity

    China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks

    Microsoft pauses KB5002907 update after Office license deactivations

    Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer

    Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

    ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Israel v Republic of Ireland: Republic of Ireland to wear black armbands for Israel game

    September 27, 2026

    Levoit’s new air purifier is for the pet odors that have taken over your apartment

    September 27, 2026

    ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration

    September 27, 2026

    Samourai Wallet Co-Founder Recounts 30-Day Prison Transfer

    September 27, 2026
    Latest Posts

    5 Best AI Notetakers (2026), Tested and Reviewed

    August 6, 2026

    All schools to get pupil attendance targets, government says

    August 6, 2026

    Trump vows to find ‘leakers’ after reports of depleted Iran war munitions | US-Israel war on Iran News

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Israel v Republic of Ireland: Republic of Ireland to wear black armbands for Israel game

    September 27, 2026

    Levoit’s new air purifier is for the pet odors that have taken over your apartment

    September 27, 2026

    ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration

    September 27, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.