'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
Researchers detailed a 'Salesbleed' attack in which agentic AI features in Salesforce can smuggle arbitrary instructions from the web across multiple apps into trusted internal Slack channels, turning corporate communications into a phishing vector.
- 'Salesbleed' attack abuses agentic AI features in Salesforce
- Malicious instructions travel from the web across multiple apps
- Target is trusted internal Slack channels used for phishing
Read next
Security