{
  "id": 9637767,
  "title": "Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing",
  "url": "https://urgent.news/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-24T19:01:15.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958"
  },
  "original_language": "en",
  "account": "Three security flaws in Salesforce Agentforce allowed attackers to steal CRM data through a zero-click method and send phishing messages under the agents' identities. The vulnerabilities, known as SalesBleed, were discovered by Zenity Labs and reported to Salesforce, which worked to fix the issues. Despite the fixes, Zenity Labs' co-founder and CTO, Michael Bargury, emphasized the difficulty in controlling AI agents and maintaining their containment. The vulnerabilities turned a public lead form into a data exfiltration channel, enabling attackers to silently steal sensitive customer information. They exploited weaknesses in Salesforce's Trusted URLs controls, which failed to register hostnames with unrecognized top-level domains and improperly parsed URLs containing certain characters. This allowed attackers to bypass the URL redaction mechanism and embed stolen CRM data in image requests to attacker-controlled servers. Additionally, the vulnerabilities enabled attackers to exploit Agentforce's integration with Slack to deliver phishing links under the agents' identities, either via an internal user or an external attacker.",
  "summary": "'SalesBleed' security flaws 'lead to very unexpected consequences'",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing",
        "url": "https://urgent.news/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-9640408",
        "published": "2026-09-24T19:01:15.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}