chiprook
← Security
SecuritySeptember 25, 2026, 20:30

Zenity finds zero-click flaws in Salesforce Agentforce

Zenity Labs disclosed SalesBleed, a zero-click attack chain in Salesforce Agentforce where hidden prompt injections in Web-to-Lead forms made an AI agent exfiltrate CRM data via DNS without any victim interaction or authentication. Salesforce fixed the URL redaction bypass on August 18.

Zenity finds zero-click flaws in Salesforce Agentforce
#Salesforce#Agentforce#Zenity
Read next
Security

Plugin4Shell: zero-click RCE hits Claude Code, Codex, Copilot and Gemini CLI

Business

Salesforce builds FDE Partner Network with 84 partners and 800+ practitioners

AI

Salesforce unveils AIforce and Koa CRM model built on NVIDIA Nemotron at Dreamforce

AI

Telstra deploys Salesforce Agentforce for AI-powered customer service