MalwareSep 24, 2026
'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
Salesbleed vulnerability allows AI agents to inject malicious instructions into Salesforce, enabling Slack phishing.
Summary
A new vulnerability dubbed 'Salesbleed' has been discovered in Salesforce, allowing malicious actors to exploit agentic AI features. Attackers can smuggle arbitrary instructions from the web across multiple applications, ultimately injecting them into trusted internal communications channels like Slack. This enables sophisticated phishing attacks by leveraging the AI's ability to interact with and send messages through these integrated platforms.
Entities
Salesforce (product)Slack (product)Agentic AI (technology)