Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing
'SalesBleed' security flaws 'lead to very unexpected consequences'
Security flaws in Salesforce Agentforce allowed attackers to steal CRM data without clicking on a link and send phishing messages under the agents' identities. Zenity Labs discovered three vulnerabilities, known collectively as SalesBleed, and reported them to Salesforce. While these attack chains are no longer functional, Zenity's co-founder and CTO Michael Bargury emphasized the challenges in controlling what agents can access and the potential consequences when guardrails are bypassed.
The first two vulnerabilities turned a public lead form into a data exfiltration channel, allowing attackers to steal sensitive customer information. The third vulnerability involved Agentforce's integration with Slack and could be used to deliver phishing links under the agents' identities. While the first two vulnerabilities have been fixed, the researchers warn that this type of vulnerability is not unique to Salesforce and can affect any agent that reads records submitted by external sources, renders links or images back to users, and holds tool access to sensitive data.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.