[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fbzo-CN9_cgSOl-YUSFV_M-ZaTW9lR9SNcgS8PAWdIs0":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"d9ebbd5a-0497-4aff-b3b3-31a0a5584d17","salesbleed-zero-click-data-exfiltration-via-salesforce-agentforce-flaws","13410c46-5aa9-4664-85a6-8e075e8de7d2","SalesBleed: Zero-Click Data Exfiltration via Salesforce Agentforce Flaws","Three vulnerabilities in Salesforce Agentforce—collectively dubbed 'SalesBleed'—allowed attackers to hijack trusted AI agents to exfiltrate sensitive data and launch phishing campaigns without requiring any user interaction. Two flaws exploited Web-to-Lead forms to bypass Trusted URL controls, enabling zero-click data theft, while a third weaponized the Agentforce-Slack integration as a phishing vector. This incident highlights the expanding attack surface introduced by AI-driven automation platforms and third-party integrations, which can inherit or amplify trust relationships in dangerous ways. Organizations must treat AI agent configurations and integration points as first-class security assets requiring rigorous review and timely patching.","**Immediate actions:**\n- Apply Salesforce's patches for the three SalesBleed vulnerabilities across all affected Agentforce instances immediately.\n- Audit and tighten Trusted URL allowlists in Salesforce to enforce least-privilege for all agent-accessible endpoints.\n- Review and restrict Agentforce-Slack integration permissions to the minimum required scope.\n\n**Configuration & hardening:**\n- Regularly review and harden AI agent configurations, treating them with the same rigor as application code and API surfaces.\n- Disable or scope-limit Web-to-Lead forms and similar public-facing intake mechanisms where full functionality is not required.\n- Enforce strict allowlisting of external services that AI agents are permitted to communicate with.\n\n**Detection & long-term improvements:**\n- Implement monitoring and alerting on anomalous Agentforce activity, including unexpected data queries or outbound requests to external URLs.\n- Establish a recurring vulnerability assessment cadence specifically targeting AI\u002Fautomation platform integrations and their trust boundaries.\n- Include AI agent platforms and SaaS integrations in your third-party risk and patch management programs.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 7: Continuous Vulnerability Management","CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 3: Data Protection","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 AC-3: Access Enforcement","NIST SP 800-53 SC-7: Boundary Protection","NIST SP 800-53 AU-6: Audit Record Review, Analysis, and Reporting","NIST CSF ID.AM-2: Software platforms and applications within the organization are inventoried","GDPR Article 25: Data Protection by Design and by Default","GDPR Article 32: Security of Processing","published","2026-09-25T10:20:19.066684+00:00","2026-09-25T10:20:18.723+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.securityweek.com\u002Fsalesbleed-flaws-in-salesforce-agentforce-enabled-zero-click-data-exfiltration\u002F","salesbleed-flaws-in-salesforce-agentforce-enabled-zero-click-data-exfiltration-150257","‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":37,"name":38,"slug":39,"description":40,"color":41},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]