Zenity Labs identified critical security gaps in Salesforce’s Agentforce platform. These defects enabled attackers to steal customer relationship management data without user interaction. The vulnerabilities also allowed bad actors to send phishing emails using the identity of AI agents. Salesforce confirmed the issues and coordinated with security researchers to fix the problems.
The flaws, collectively named SalesBleed, created a dangerous pathway for malicious input. Attackers could poison incoming sales leads with specific code or instructions. Once processed by the AI agents, this poisoned data triggered unintended actions. The system then executed these commands silently in the background. This mechanism bypassed traditional security checks that rely on user clicks or active engagement. Consequently, sensitive CRM records were exfiltrated while the system appeared normal to administrators.
The core issue lay in how Agentforce handled untrusted input from external sources. Zenity Labs demonstrated that a crafted lead entry could manipulate the AI’s decision-making process. The agent would interpret the malicious payload as a valid instruction. It then accessed internal databases to retrieve relevant information. This data was subsequently sent to an attacker-controlled endpoint. No human intervention was required to initiate the breach. The entire process occurred within the automated workflow. This made detection significantly more difficult for standard monitoring tools.
A second major vulnerability allowed attackers to hijack the communication channels of the AI agents. By exploiting the same poisoning technique, intruders could force the agent to send emails. These messages appeared to come directly from the trusted AI assistant. The content included convincing links designed to trick recipients into revealing credentials. Because the sender identity matched the known agent, users often lowered their guard. This social engineering attack leveraged the inherent trust placed in automated systems. The result was a highly effective phishing campaign that blended seamlessly with legitimate business operations.
Salesforce responded quickly after receiving the detailed report from Zenity Labs. The company worked closely with the research team to validate the findings. They developed patches to sanitize incoming data before it reached the AI logic layer. Additional controls were implemented to restrict outbound communications initiated by agents. These updates aimed to close the gap between input validation and action execution. The collaboration highlighted the growing need for specialized security testing in AI-driven platforms.
The discovery underscores the risks of integrating complex AI models into critical business infrastructure. As organizations deploy autonomous agents to handle customer interactions, the attack surface expands. Traditional perimeter defenses are less effective against logical flaws in automated workflows. Companies must now audit how their AI systems process external data. Security teams should verify that agents cannot be manipulated into executing unauthorized tasks. Future deployments will likely require stricter sandboxing and continuous monitoring. The SalesBleed incident serves as a warning for the broader industry. It highlights the urgent need for robust security protocols in the era of autonomous software.
What is SalesBleed? SalesBleed refers to a set of three vulnerabilities in Salesforce Agentforce. These flaws allowed attackers to steal data and send phishing emails via AI agents.
How did the zero-click attack work? Attackers injected malicious code into new sales leads. The AI agents processed this data and automatically executed the hidden commands. No user interaction was needed to trigger the exploit.
Did Salesforce fix the issues? Yes, Salesforce patched the vulnerabilities after reporting. They added safeguards to filter input and control agent behavior. The fixes were released in coordination with Zenity Labs.