Salesforce Agentforce Flaws Exposed in 'SalesBleed' Vulnerability
Three vulnerabilities in Salesforce's Agentforce platform have been discovered by cybersecurity firm Zenity Labs. The issues, dubbed 'SalesBleed', could have allowed attackers to steal CRM data and send phishing messages through internal Slack channels.
The attack started with the Web-to-Lead feature, which allows companies to place forms on their websites for customers to submit information that automatically enters Salesforce as a lead. An attacker could submit a specially crafted lead containing hidden instructions intended for an Agentforce AI agent, which would remain dormant until an employee later asked the agent to read or interact with the malicious lead.
Researchers found that two of the three vulnerabilities allowed zero-click CRM data exfiltration, meaning employees didn't need to click on anything for sensitive information to be transmitted. The third vulnerability involved Agentforce's integration with Slack, where attackers could manipulate an agent into posting phishing messages in internal channels.