Salesforce Agentforce Flaws Enable Zero-Click Data Theft and AI Agent Impersonation

  • Zenity Labs disclosed three vulnerabilities in Salesforce Agentforce, dubbed 'SalesBleed', enabling zero-click data exfiltration and AI agent impersonation.
  • Two vulnerabilities allow sensitive CRM data to be transmitted to attacker-controlled infrastructure without user interaction.
  • The third vulnerability enables phishing attacks via Slack using the trusted identity of an Agentforce-connected AI agent.
  • Zenity Labs responsibly disclosed the findings to Salesforce, which remediated the issues within approximately two weeks.

The discovery of SalesBleed highlights the critical need for robust security measures in AI agent integrations, particularly as enterprises increasingly rely on these agents for sensitive operations. The vulnerabilities underscore the importance of layered visibility and real-time monitoring to prevent data exfiltration and unauthorized actions. As AI agents become more autonomous, the potential for unexpected consequences from design flaws grows, necessitating a proactive approach to security governance.

Security Boundaries
How the bypass of Trusted URLs in Agentforce will impact the design and implementation of security boundaries for AI agents.
Enterprise AI Adoption
Whether enterprises will increase monitoring and governance of AI agents following these disclosures.
AI Agent Autonomy
The pace at which AI agents become more autonomous and the potential risks associated with their increased autonomy.