Urgent.News

What's breaking now, across thousands of outlets.

Tech

Salesforce patches Agentforce flaws enabling zero-click data theft

Salesforce has patched three vulnerabilities in its Agentforce artificial intelligence platform that researchers said could have enabled unauthenticated attackers to extract sensitive customer relationship management data without victims clicking malicious links. The weaknesses, collectively named SalesBleed by Zenity Labs, were publicly disclosed on September 24 after fixes were completed and…

Salesforce has addressed three security flaws in its Agentforce AI platform, which researchers discovered could permit unauthorized data extraction from customer relationship management systems without requiring users to click on malicious links. These vulnerabilities, dubbed SalesBleed by cybersecurity firm Zenity Labs, were made public on September 24 following patches and testing.

Salesforce confirmed it had not detected any exploitation of these flaws. The attack process starts with the Web-to-Lead feature in Salesforce, allowing external parties to submit data directly into CRM records. Attackers could insert hidden instructions within a lead submission, which would remain in the database until an Agentforce agent reviewed the leads.

This action could cause the agent to interpret the embedded text as commands, leading it to retrieve sensitive data from the Accounts table. The attackers then exploited weaknesses in Agentforce's Trusted URLs protection, a feature meant to block unauthorized URLs. By manipulating unrecognised top-level domains and characters, researchers created a pathway for data exfiltration, allowing stolen CRM data to be inserted into a subdomain controlled by the attacker and retrieved via an HTML image tag.

Additionally, if Agentforce was integrated with Slack, the compromise could allow attackers to send phishing messages directly from Slack threads. Furthermore, another flaw enabled compromised agents to be used as phishing channels within Slack. The company has since updated its Trusted URLs mechanism and Slack defaults to require confirmation for certain actions, identifying the user who triggered the action.

Zenity Labs reported these vulnerabilities to Salesforce on June 1, and the company acknowledged them the following day. The fixes for the URL bypass were implemented on August 19, and all patches were confirmed by September 21. This incident highlights the risks associated with integrating AI agents that have access to privileged data and the potential for malicious actors to exploit seemingly innocuous data entries to gain deeper access to corporate systems.

Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at thearabianpost.com →

More in Tech

More from Saturday 26 September →