Agents
SalesBleed: one poisoned Web-to-Lead form let Agentforce leak CRM data with zero clicks and send phishing under its Slack identity
Zenity Labs disclosed three Agentforce flaws on 24 September. Two are zero-click exfiltration paths: a Trusted URLs bypass that leaked Accounts data through image and DNS requests, and a Slack link-unfurling variant. The third let an attacker post phishing messages through the agent's 'Reply to Slack Thread' action with no approval or attribution. The injection sits dormant in a public lead form until an employee asks the agent about leads. Salesforce was notified on 1 June, confirmed the Trusted URLs fix on 19 August, and fixed all three by 21 September. Any public form that writes to a table an agent later reads is an injection entry point, and URL rendering is where the data leaves.
↳ Follow the thread