Salesforce Agentforce Flaws Enable Zero-Click Data Theft and AI Agent Impersonation
Event summary
- Zenity Labs disclosed three vulnerabilities in Salesforce Agentforce, dubbed 'SalesBleed', enabling zero-click data exfiltration and AI agent impersonation.
- Two vulnerabilities allow sensitive CRM data to be transmitted to attacker-controlled infrastructure without user interaction.
- The third vulnerability enables phishing attacks via Slack using the trusted identity of an Agentforce-connected AI agent.
- Zenity Labs responsibly disclosed the findings to Salesforce, which remediated the issues within approximately two weeks.
The big picture
The discovery of SalesBleed highlights the critical need for robust security measures in AI agent integrations, particularly as enterprises increasingly rely on these agents for sensitive operations. The vulnerabilities underscore the importance of layered visibility and real-time monitoring to prevent data exfiltration and unauthorized actions. As AI agents become more autonomous, the potential for unexpected consequences from design flaws grows, necessitating a proactive approach to security governance.
What we're watching
- Security Boundaries
- How the bypass of Trusted URLs in Agentforce will impact the design and implementation of security boundaries for AI agents.
- Enterprise AI Adoption
- Whether enterprises will increase monitoring and governance of AI agents following these disclosures.
- AI Agent Autonomy
- The pace at which AI agents become more autonomous and the potential risks associated with their increased autonomy.
Related topics
