'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing

Sep 24
1 min read
Vulnerabilities in Salesforce Agentforce, collectively dubbed "Salesbleed" by researchers, could expose customers' internal data and, worse, allow attackers to phish employees from within trusted company channels.
As so often happens with powerful, interconnected AI platforms that excite customers and investors, security and visibility remain hard problems to solve. Researchers at Zenity noted that the three "Salesbleed" weaknesses in Agentforce allow hackers to slowly bleed data from victims via Web-to-lead forms. The most interesting finding, though, is how this seemingly modest Web-to-lead vulnerability can be combined with normal Agentforce workflows to ultimately phish employees from within their most trusted Slack channels.
Comments