$ techbeacon▋
CVE & Exploits

AI‑Powered ‘Salesbleed’ Attack Uses Salesforce Agents to Funnel Phishing Content Into Slack

AI‑Powered ‘Salesbleed’ Attack Uses Salesforce Agents to Funnel Phishing Content Into Slack

Security researchers have identified a new attack chain, dubbed “Salesbleed,” that exploits the artificial‑intelligence agents built into Salesforce to insert malicious instructions into Slack messages. By chaining the two widely deployed SaaS platforms, the technique can deliver phishing content that appears to originate from trusted internal channels, increasing the likelihood that recipients will follow the lure.

The core of the method relies on “agentic AI” capabilities that allow Salesforce’s automated assistants to retrieve arbitrary data from external web sources. Once the malicious payload is fetched, the agents forward it through the native Salesforce‑Slack integration, which is designed to streamline collaboration by posting updates directly into designated Slack workspaces. Because the messages are generated by a legitimate integration, they bypass many conventional email‑oriented phishing defenses.

Both Salesforce and Slack are integral to the daily workflows of countless enterprises, with the former serving as a customer‑relationship management hub and the latter acting as a primary instant‑messaging platform. Their tight coupling enables sales and support teams to share records, alerts, and status changes in real time. This convenience, however, also creates a trusted conduit that attackers can weaponize when the underlying automation is compromised.

Organizations that rely on these tools face heightened risk of credential theft, unauthorized data access, and broader supply‑chain compromise. The deceptive nature of the messages can lead employees to disclose login details, click malicious links, or execute unintended commands, potentially granting adversaries footholds within otherwise secure networks.

In response, Salesforce has issued an advisory urging customers to review integration permissions and to apply recent hardening updates to AI agent configurations. Slack’s security team has similarly recommended tighter app‑approval processes and the use of message‑verification mechanisms such as digital signatures. Both vendors emphasize the importance of monitoring for anomalous inter‑app traffic and limiting the scope of automated agents to only necessary functions.

The discovery underscores a growing trend where adversaries leverage generative AI and automation to blur the line between legitimate workflow automation and malicious activity. Security professionals are now urged to extend threat‑modeling practices to cover AI‑driven integrations and to adopt zero‑trust principles that verify the provenance of every cross‑platform message, not just traditional email vectors. As AI capabilities continue to mature, the industry can expect more sophisticated attempts to hide malicious intent behind trusted services.

Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related