SalesBleed: flaws in Salesforce’s AI agents allowed zero-click CRM data theft
Researchers at Zenity Labs have discovered three vulnerabilities, dubbed “SalesBleed”, in Agentforce, Salesforce’s artificial intelligence agents. The attack started with something as innocent as a lead capture form on a public website (Web-to-Lead): the attacker typed hidden instructions aimed at the AI into it, a technique known as indirect prompt injection. When an employee later asked the agent about new leads, the AI read those instructions and carried them out without anyone noticing.
From there, the agent queried the CRM’s accounts table and sent the data to an attacker-controlled server hidden in image requests, getting around Salesforce’s trusted URL controls. It could also post messages in Slack threads without user confirmation, allowing anonymous phishing campaigns from an internal channel everyone trusts. Zenity notified Salesforce on 1 June and all three vulnerabilities were fixed on 21 September. The case shows that AI agents connected to several applications open new doors into company data.
Tip from Soporte Informático 360
If your company uses AI agents connected to your CRM, email or Slack, keep the data and actions they can access to a minimum, require human confirmation before they send messages or share information, and treat any text coming from public forms as untrusted.
Source: The Register. Summary prepared by our team for informational purposes.
IT maintenance for businesses
Preventive and corrective maintenance of your equipment to avoid downtime and extend its useful life.