Three vulnerabilities in Salesforce Agentforce, known as SalesBleed, enabled attackers to hijack AI agents for data theft and phishing attacks.
The 'SalesBleed' attack chain targets Salesforce Agentforce, allowing attackers to use prompt injection to silently exfiltrate sensitive CRM data via zero-click methods.