Story · Zenity Labs
SalesBleed: Indirect Prompt Injection and 0-Click Data Exfiltration on Agentforce (Zenity Labs)
blog post · Story page
Zenity Labs reached Agentforce account data through a public Web-to-Lead form, with no login and no victim click, and got it out over a DNS query. It reports bypassing the guardrails and the Trusted URLs redaction layer; Salesforce has remediated.
In plain words
- Zenity Labs found a way to steal Salesforce account information without logging in or requiring the account owner to click anything.
- The attack put malicious instructions in a public form for potential customers that Salesforce's Agentforce assistant could read.
- The attack sent stolen information through a request normally used to find a website's address, bypassing security filters.
- Salesforce fixed the flaw to protect customers' account information from this attack.
Appeared in
- Forged control tokens blank an agent's reasoning while the tool call still fires
Sep 25, 2026 · in the sections
Subscribe
Get the brief in your inbox
Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.
- Weekdays at 8:45am IST, one lead story and 6 to 9 items.
- Sundays, an argued synthesis rather than a recap.
- One click to leave, and quiet days say so in the subject line.