Story · Zenity Labs

SalesBleed: Indirect Prompt Injection and 0-Click Data Exfiltration on Agentforce (Zenity Labs)

blog post · Story page

Zenity Labs reached Agentforce account data through a public Web-to-Lead form, with no login and no victim click, and got it out over a DNS query. It reports bypassing the guardrails and the Trusted URLs redaction layer; Salesforce has remediated.

In plain words

  • Zenity Labs found a way to steal Salesforce account information without logging in or requiring the account owner to click anything.
  • The attack put malicious instructions in a public form for potential customers that Salesforce's Agentforce assistant could read.
  • The attack sent stolen information through a request normally used to find a website's address, bypassing security filters.
  • Salesforce fixed the flaw to protect customers' account information from this attack.

Appeared in

Subscribe

Get the brief in your inbox

Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.

  • Weekdays at 8:45am IST, one lead story and 6 to 9 items.
  • Sundays, an argued synthesis rather than a recap.
  • One click to leave, and quiet days say so in the subject line.
How often

Weekdays 8:45am IST + Sundays. Unsubscribe in one click.

You're asking for The Agentic Brief by email at the cadence you picked. You can unsubscribe in one click from any issue, and your address is never sold or shared.