Researchers Detail 'Salesbleed' Flaws in Salesforce Agentforce Enabling Slack Phishing
Security firm Zenity disclosed three vulnerabilities, collectively named 'Salesbleed,' in Salesforce's Agentforce AI platform. The flaws let attackers plant malicious prompts inside Web-to-lead forms, which AI agents then process, allowing gradual extraction of internal data and, when combined with normal Agentforce workflows, the ability to send phishing messages to employees through their trusted Slack channels.
GoKawiil's interpretation of the reporting above, not reported fact.
The findings build on earlier work by Noma Security showing Web-to-lead forms as an entry point for prompt injection, suggesting attackers are increasingly targeting the trust boundaries between AI agents and everyday business tools. Because Slack is often treated as an inherently safe internal channel, this technique could make phishing attempts far more convincing and harder for employees to detect. The case underscores broader industry concerns that fast-moving AI agent platforms may outpace the security and visibility controls needed to contain them.
- Zenity researchers identified three flaws in Salesforce Agentforce dubbed 'Salesbleed.'
- Attackers can embed malicious AI prompts in Web-to-lead forms to exfiltrate data and trigger phishing via Slack.
- The exploit builds on a related Web-to-lead vulnerability class first reported by Noma Security a year earlier.
Source: darkreading.com — Nate Nelson, 2026-09-24
Published there as: “'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.