Salesforce has invested heavily in its Agentforce platform to notable success, but new research found its security lacking, with investigators able to pull sensitive account data without ever logging in.
Security company Zenity Labs published research on two attacks exploiting ways to hijack Agentforce agents to send phishing messages and enable 0-click data exfiltration, using bugs since fixed by Salesforce.
Researcher João Donato said the vulnerabilities, collectively dubbed SalesBleed, show that “hijacking enterprise agents via untrusted external data remains a broader risk, and any agent integrated into trusted workplace tools can significantly expand an attacker's reach.”