Salesforce’s Agentforce AI Agents Found Vulnerable to Zero‑Click Exploits, Raising AI Security Concerns
Security researchers have identified a series of zero‑click flaws, dubbed “SalesBleed,” affecting Salesforce’s Agentforce AI agents, a tool that automates customer‑relationship‑management (CRM) tasks. The vulnerabilities allow threat actors to inject malicious prompts and siphon data out of a company’s CRM system without any user interaction, exposing sensitive business information to external parties.
The core of the issue lies in how Agentforce processes natural‑language prompts. By crafting specially designed inputs, an attacker can manipulate the agent’s reasoning chain—a technique known as prompt injection—to retrieve or alter data that should remain private. Once the compromised agent generates a response, the extracted information is covertly transmitted via DNS queries, a method that can bypass many traditional network monitoring solutions.
Salesforce’s Agentforce, introduced to streamline sales workflows through generative‑AI assistance, has been adopted by thousands of enterprises worldwide. The discovery of these flaws highlights a broader risk inherent to AI‑driven assistants that operate with elevated privileges on critical business platforms. As organizations increasingly embed such agents into their daily operations, the attack surface expands, making robust validation of AI inputs a pressing priority.
The findings were first detailed in a report by Infosecurity Magazine, which cited internal testing that demonstrated successful data exfiltration from a mock CRM environment. Although the researchers did not disclose the exact scope of compromised data, they warned that any organization relying on Agentforce could be vulnerable to unauthorized access to contacts, sales pipelines, and financial records.
In response, Salesforce has acknowledged the report and indicated that its security team is actively developing patches to remediate the identified weaknesses. The company urged customers to apply existing security best practices, such as restricting DNS traffic, monitoring AI agent logs, and limiting the agents’ access rights until the fixes are deployed. No public statement provided a timeline for the release of updates.
Industry analysts view the SalesBleed revelations as a cautionary signal for the rapid rollout of AI agents across enterprise software. They recommend that firms conduct thorough threat modeling for any AI component, enforce strict input sanitization, and maintain visibility into outbound network communications. As regulators and privacy advocates scrutinize AI deployment, incidents like this may accelerate the push for standardized security frameworks tailored to generative‑AI tools.
Comments (0)
Be the first to comment.
Join the discussion