Executive Summary
The 'Salesbleed' vulnerabilities discovered in September 2026 by Zenity researchers exploit Salesforce Agentforce AI agents to enable sophisticated phishing attacks through trusted internal Slack channels. Attackers inject malicious prompts via Web-to-lead forms, leveraging AI agents' permissions to exfiltrate data and send phishing messages that appear to originate from legitimate employees or IT help desk personnel. This attack chain demonstrates how agentic AI platforms create new attack vectors by combining legitimate business processes with inadequate security controls, particularly around URL filtering and message attribution.
This incident highlights the growing security challenges posed by autonomous AI agents in enterprise environments, as organizations rapidly deploy agentic systems without adequate visibility and control mechanisms. The vulnerability underscores the critical need for comprehensive AI governance frameworks as businesses increasingly rely on AI agents with elevated permissions across interconnected cloud platforms.
Why This Matters Now
Agentic AI adoption is accelerating across enterprises, but security controls are lagging behind implementation speed. The Salesbleed vulnerabilities expose systemic risks in AI agent architectures that could be exploited across multiple platforms as attackers adapt their tactics to target autonomous systems.
Attack Path Analysis
Attackers exploited Salesforce Agentforce vulnerabilities by injecting malicious prompts through Web-to-lead forms, leveraging AI agents' elevated permissions to access internal data and ultimately execute phishing attacks through trusted Slack channels. The attack chain demonstrates how agentic AI platforms can be weaponized to bridge external attack vectors with internal communication systems, bypassing traditional security boundaries through prompt injection and social engineering.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers submitted specially crafted AI instructions through publicly accessible Salesforce Web-to-lead forms, exploiting the platform's willingness to accept near-arbitrary data from prospects and embedding malicious prompts targeting Agentforce AI agents
MITRE ATT&CK® Techniques
Spearphishing Attachment
Exploit Public-Facing Application
Process Hollowing
Malicious File
Disable or Modify Tools
Exfiltration Over C2 Channel
Web Protocols
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Engineering Techniques for Secure Development
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – Third-party Risk Management
Control ID: Article 8
CISA ZTMM 2.0 – Application Security
Control ID: Function 4
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21(2)(a)
ISO 27001 – Secure Development Policy
Control ID: A.14.2.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Salesforce Agentforce vulnerabilities enable AI prompt injection attacks, allowing data exfiltration and internal phishing through Web-to-lead forms and Slack integrations.
Marketing/Advertising/Sales
Web-to-lead form exploitation targets sales processes, enabling attackers to inject malicious prompts that compromise CRM data and internal communications channels.
Financial Services
AI agent vulnerabilities expose sensitive financial data through prompt injection, with compliance risks under HIPAA, PCI-DSS, and NIST frameworks for data protection.
Professional Training
Agentic AI security gaps affect training platforms using Salesforce integrations, creating risks for data exfiltration and social engineering through trusted communication channels.
Sources
- 'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishinghttps://www.darkreading.com/application-security/salesbleed-exploits-salesforce-agents-slack-phishingVerified
- Salesforce Security Center - Agentforce Security Documentationhttps://help.salesforce.com/s/articleView?id=sf.security_overview.htmVerified
- NIST AI Risk Management Frameworkhttps://www.nist.gov/itl/ai-risk-management-frameworkVerified
- Zenity Security Research - AI Agent Security Analysishttps://zenity.io/researchVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain this AI prompt injection attack by segmenting cloud service communications and controlling cross-platform data flows between Salesforce and Slack integrations, reducing the attacker's ability to leverage elevated AI agent permissions across multiple SaaS platforms.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero Trust fabric policies would likely limit the scope of malicious prompt processing by constraining AI agent access paths and reducing the blast radius of compromised automation workflows within the cloud environment.
Control: Zero Trust Segmentation
Mitigation: Zero Trust segmentation would likely constrain AI agent privilege scope by isolating automation workloads and reducing the breadth of resources accessible through compromised agent credentials within segmented cloud environments.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely constrain cross-platform integration flows and reduce the attacker's ability to pivot between SaaS platforms by limiting inter-service communication paths and monitoring integration traffic patterns.
Control: Multicloud Visibility & Control
Mitigation: Enhanced visibility controls would likely detect anomalous AI agent communication patterns and constrain persistent access by monitoring cross-service interactions and identifying unusual data flow behaviors within multicloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security policies would likely constrain outbound data flows from compromised AI agents and reduce exfiltration scope by blocking unauthorized external connections and monitoring data transfer patterns to suspicious domains.
While Zero Trust controls would likely reduce the scope of social engineering campaigns by constraining cross-platform access, residual risk remains for phishing messages already posted in trusted communication channels to compromise additional user credentials.
Impact at a Glance
Affected Business Functions
- Customer Relationship Management (CRM)
- Sales Lead Processing
- Internal Communications (Slack)
- Marketing Automation
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of customer lead data, internal Salesforce records, and compromise of trusted internal Slack communications channels through phishing attacks. The vulnerability allows extraction of CRM data and enables social engineering attacks within corporate messaging platforms.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to limit AI agent permissions and prevent lateral movement between Salesforce and Slack integrations
- • Deploy Multicloud Visibility & Control to detect anomalous AI agent interactions, repeated malformed requests, and suspicious automation patterns across agentic platforms
- • Enable Egress Security & Policy Enforcement with FQDN filtering to block unauthorized data exfiltration attempts to attacker-controlled domains via AI agents
- • Establish Cloud Native Security Fabric (CNSF) controls specifically designed for agentic AI systems, including prompt injection detection and AI agent behavior monitoring
- • Deploy Threat Detection & Anomaly Response capabilities to baseline normal AI agent behavior and alert on deviations that may indicate prompt injection or abuse of agent capabilities



