{
  "id": 9640408,
  "title": "Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing",
  "url": "https://urgent.news/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-9640408",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-24T19:01:15.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958"
  },
  "original_language": "en",
  "account": "Security flaws in Salesforce Agentforce allowed attackers to steal CRM data without clicking on a link and send phishing messages under the agents' identities. Zenity Labs discovered three vulnerabilities, known collectively as SalesBleed, and reported them to Salesforce. While these attack chains are no longer functional, Zenity's co-founder and CTO Michael Bargury emphasized the challenges in controlling what agents can access and the potential consequences when guardrails are bypassed. The first two vulnerabilities turned a public lead form into a data exfiltration channel, allowing attackers to steal sensitive customer information. The third vulnerability involved Agentforce's integration with Slack and could be used to deliver phishing links under the agents' identities. While the first two vulnerabilities have been fixed, the researchers warn that this type of vulnerability is not unique to Salesforce and can affect any agent that reads records submitted by external sources, renders links or images back to users, and holds tool access to sensitive data.",
  "summary": "'SalesBleed' security flaws 'lead to very unexpected consequences'",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing",
        "url": "https://urgent.news/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous",
        "published": "2026-09-24T19:01:15.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}