Tech Shots
AI news flashes
עברית
Tools

Salesforce fixed SalesBleed — zero-click CRM leak flaws in Agentforce

Zenity Labs disclosed SalesBleed, three now-fixed flaws in Salesforce Agentforce: two let a poisoned entry from a public lead form quietly leak CRM data with no employee click — one through the agent’s chat replies, one through Slack link previews — and a third let the agent’s Slack identity be abused for phishing. Per The Register and Zenity’s announcement, the issues were reported to Salesforce on June 1, the company worked with the researchers on fixes, and on September 21 Zenity confirmed all three were closed. High-level only: no PoC, no exploit steps, no payloads. This is Zenity’s SalesBleed research on Agentforce, not Noma’s 2025 ForcedLeak bug and not the OpenAI–Hugging Face sandbox escape.

Source: The Register