chiprook
← Security
SecuritySeptember 27, 2026, 22:40

SalesBleed: Three Zero-Click Flaws Found in Salesforce Agentforce

Zenity Labs disclosed three zero-click vulnerabilities in Salesforce Agentforce that let attackers use prompt injection in a web form to make the AI agent exfiltrate CRM data via DNS queries. All flaws are patched, but the pattern applies to any enterprise agent.

SalesBleed: Three Zero-Click Flaws Found in Salesforce Agentforce
#Salesforce#Agentforce#Zenity
Read next
Security

'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing

AI

Dreamforce 2026: AI agents shift from demos to measurable outcomes

Business

Salesforce builds FDE Partner Network with 84 partners and 800+ practitioners

AI

Salesforce unveils AIforce and Koa CRM model built on NVIDIA Nemotron at Dreamforce