Back Darkreading 'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
Agentic AI can smuggle arbitrary instructions from the Web, across multiple apps, into trusted internal communications channels.
Vulnerabilities in Salesforce Agentforce, collectively dubbed "Salesbleed" by researchers, could expose customers' internal data and, worse, allow attackers to phish employees from within trusted company channels.
As so often happens with powerful, interconnected AI platforms that excite customers and investors, security and visibility remain hard problems to solve. Researchers at Zenity noted that the three " Salesbleed " weaknesses in Agentforce allow hackers to slowly bleed data from victims via Web-to-lead forms. The most interesting finding, though, is how this seemingly modest Web-to-lead vulnerability can be combined with normal Agentforce workflows to ultimately phish employees from within their most trusted Slack channels.
Building on Issues With Salesforce Web-to-Lead Forms
One year ago, researchers at Noma Security revealed a neat little way to steal corporate data using Salesforce . The trick began with Web-to-lead forms: one of the few contexts on the Internet in which companies will willingly accept near-arbitrary data sent by random individuals. Essentially, sales prospects fill out a registration form to gain access to something, and that lead data is then imported to Salesforce. In the past, attackers might have used Web-to-lead forms to send malicious code. In these agentic days, the researchers figured they could send malicious prompts.
Related: Prompt-Injection Bug Hits $4B Agentic AI App 'Manus'
If an attacker presumed that their target was running Agentforce AI agents, it turned out that they could plant a specially crafted AI instruction — for example, an instruction to exfiltrate data to an attacker-controlled URL — in a Web-to-lead form. An agent on the other end of the interaction would ingest and process the instruction, and execute the request inside of the victim company's environment. Salesforce responded to Noma's findings by quickly polishing its rules around URLs that an attacker might use to carry out such an attack. Dark Reading noted at the time that "structural fixes to how its AI processes instructions however remain elusive for now."
This Band-Aid failed to treat the underlying infection, and now, a year later, a new set of researchers from Zenity found that they could perform largely the same attack, using simple workarounds to the URL filtering rules Salesforce implemented in response to last year's findings.
The researchers stressed how convenient their attack was. For one thing, there's no way to identify, suspend, or in any other way punish any passing Internet miscreant using Web-to-lead forms. And by having an AI agent do their bidding for them, attackers can effortlessly piggyback on the typically healthy permissions Salesforce customers willingly grant their bots.
Related: GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks
Exploiting Slack via Salesforce Agents
There was just one shortcoming in Zenity's exploit: For any given prompt, an attacker could exfiltrate only as much data as would fit into one subdomain string. That's hardly enough to cause much damage, unless the attacker were looking for very precise data, or automated hundreds or thousands of malicious requests.
But reading and sending data are only two among many powers afforded to Agentforce agents. If agents can do a thousand and one other things for legitimate users, could they do those same things for an attacker?
For example, users can deploy Salesforce agents directly to Slack. Slack agents can be assigned various permissions, in the form of "subagents," which allow them to read or write data. To ensure that they don't perform unwanted actions, agents can be configured to require user confirmation first. They also come with built-in attribution, identifying the human user responsible for a particular agentic action.
However, these controls were missing when it came to an agent's ability to to a Slack thread . Zenity researchers reasoned that if an external attacker could inject a malicious prompt into a Web-to-lead form, instead of just exfiltrating data, the instruction could induce a Salesforce bot to to an internal company Slack thread, and nothing would stop them from doing it. The message could incorporate social engineering, with a phishing link leveraging those previously described gaps in Salesforce's trusted URL protections. Without attribution, it could look as if the message was sent by a real employee or IT help desk. In a trusted, internal communications channel, it's likely that nobody would suspect malicious intent.
Related: How AI Agents Can Trigger Runaway Costs for Enterprises
Salesforce Hardens Agentforce Against Phishing
In a statement to Dark Reading, Salesforce acknowledged the vulnerabilities, which do not have CVE numbers, and noted that there has been no evidence that real attackers have exploited them. The company has "updated the default settings for certain Agentforce actions in Slack to require user confirmation before sending messages, and [is] communicating directly with customers to help them review their configurations and make the recommended changes," a spokesperson wrote.
The company also acknowledged that its response to last year's Web-to-lead vulnerability was a quick fix, rather than a comprehensive one. This time around, it has implemented what it believes to be a more robust solution.
Previously, Salesforce's URL redaction control relied on regular expression (regex) matching to identify untrusted URLs in AI agent outputs. Essentially, it checked whether a string of text looked like a URL, allowing clever researchers to conceal their domains in unexpected formats. The company says that it now uses spec-conformant URL parsing, which more meaningfully breaks down and interprets where potential URL strings lead.
Besides the overhauled URL parsing system, Salesforce is also consolidating its URL inspection process. Whereas previously, different parts in an agentic workflow might have each acted upon a URL, now all URL-related AI traffic is funneled through a single gateway that applies more consistent inspection and security rules.
Deeper Issues Plague Agentic Tech
Time will tell whether researchers will break Salesforce's fixes all over again. And as Zenity's analysts point out, there are more structural weaknesses to agentic platforms that URL policies can't account for.
"We've been saying it for years now: The more power you give agents, the more dangerous they are," says Tamir Ishay Sharbat, director of security research at Zenity. "The minute that an agent has the power to send messages by itself to multiple channels, for example, it becomes something that you can abuse. And when you give them access to both sensitive information — your accounts payable, leads, contracts, etc. — and external channels [like Web-to-lead forms], this combination is very toxic."
On top of that toxic combination, agents also have a visibility problem .
"When you buy enterprise software, you assume that it will have logs — that it will have a clear understanding of who did what and why," notes Zenity chief technology officer Michael Bargury. "With agents, because everybody's building fast, the entire market is building black boxes. That makes them more difficult to trust."
"You cannot look at the reasoning, you cannot look at what it does behind the scenes — you only get summaries," Bargury laments. "That's not just a problem in Salesforce; that's pervasive across the industry."
Nate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media.
He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify.
He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself.
Want more Dark Reading stories in your Google results?
The State of Cloud Security: The Latest Challenges
The State of Cloud Security: The Latest Challenges
How Organizations Are Managing Incident Response
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Essential News & Insights from Black Hat USA 2025
Essential News & Insights from Black Hat USA 2025
Effective Alert Triage: Reducing Noise and Finding Real Threats
Effective Alert Triage: Reducing Noise and Finding Real Threats
Cybersecurity Outlook 2027
Cybersecurity Outlook 2027
Threat Exposure Analytics: Measuring and Communicating Security Risk
Threat Exposure Analytics: Measuring and Communicating Security Risk
Benchmark Scores Are a False Flag
Benchmark Scores Are a False Flag
Building an Effective Red Team: Beyond Penetration Testing
Building an Effective Red Team: Beyond Penetration Testing
Supply Chain Attack Secretly Installs OpenClaw for Cline Users
Chinese Hackers Hijack Notepad++ Updates for 6 Months
Trump Administration Rescinds Biden-Era Software Guidance
Microsoft Fixes Exploited Zero Day in Light Patch Tuesday
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
