Multiple outlets report that a set of vulnerabilities dubbed “SalesBleed” affects Salesforce’s Agentforce AI agents, allowing attackers to hijack trusted agent activity and exfiltrate data without user action. The issue is described as involving prompt injection, where a malicious input can manipulate an agent’s behavior to access or disclose information, and may also enable phishing-related activity.
SecurityWeek and Infosecurity Magazine both frame the risk as a broader exposure of CRM and related data through AI agent misuse. Infosecurity Magazine emphasizes how the weaknesses could be used for “wider AI agent risk,” specifically citing techniques such as DNS-based exfiltration. Across the coverage, the differing angles focus on the mechanism (prompt injection and DNS exfiltration) and the potential outcomes (data theft and downstream phishing), while agreeing that the vulnerabilities can be exploited in a zero-click manner by leveraging agent trust.
All reports characterize the findings as significant for organizations using Salesforce Agentforce, highlighting the need to address the vulnerabilities and reduce exposure to malicious prompts.