The Containment Era is here. →Explore

Executive Summary

In June 2024, researchers at Noma Security identified a severe vulnerability in Salesforce's Agentforce AI agents, termed 'ForcedLeak'. By exploiting prompt injection via web-to-lead forms, attackers were able to manipulate Agentforce into exfiltrating sensitive CRM data, including PII, corporate secrets, and transactional details, to unauthorized locations. The vulnerability hinged on whitelist misconfigurations of trusted domains and the agent’s overly broad prompt interpretation, leading to an attacker-controlled data leak chain. Salesforce addressed data exfiltration by patching URL restrictions and acquiring an expired trusted domain but ongoing risks persist with agentic AI’s prompt processing logic.

The incident underscores the growing challenges as mainstream SaaS platforms rapidly integrate autonomous GenAI features, often lacking robust input validation and security boundaries. High CVSS-scored issues like ForcedLeak exemplify the urgent need for zero trust guardrails and more resilient AI security frameworks given the increasing velocity and sophistication of prompt injection attacks.

Why This Matters Now

The accelerated adoption of agentic AI in enterprise SaaS, without mature security controls, has created a new attack surface. Incidents like ForcedLeak highlight urgent gaps, as attackers weaponize prompt injection and misconfigured trust to exfiltrate sensitive data from business-critical platforms, raising immediate concerns for compliance and operational security.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The incident revealed weaknesses in data exfiltration controls, prompt validation, and trusted domain management, highlighting gaps with frameworks like HIPAA, PCI DSS, and NIST 800-53 regarding AI-driven data flows.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Applying Zero Trust segmentation, network policy enforcement, and real-time egress controls would have restricted agent over-permissioning, blocked malicious outbound data flows, and detected anomalous AI-driven behaviors, sharply limiting kill chain progression. CNSF and related controls can provide defense-in-depth by isolating workloads, monitoring east-west and egress traffic, and enabling rapid detection and response to agentic AI abuse.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Inline inspection and policy enforcement would detect or block malicious prompt attempts at entry.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Microsegmentation would enforce role boundaries, confining agents to only required data and actions.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Visibility and control of internal service-to-service traffic would prevent unauthorized movement.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Outbound filtering would block egress attempts to untrusted or expired domains.

Exfiltration

Control: Cloud Firewall (ACF)

Mitigation: Outbound firewalling detects and blocks data exfiltration to unauthorized domains.

Impact (Mitigations)

Anomaly detection would alert security teams to unusual AI agent activity, enabling rapid containment.

Impact at a Glance

Affected Business Functions

  • Sales
  • Marketing
  • Customer Relationship Management
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of customer contact information, sales pipeline data, internal communications, and historical interaction records.

Recommended Actions

  • Implement robust Zero Trust Segmentation to ensure AI agents have least-privileged access only to needed CRM data and services.
  • Enforce granular Egress Security and update trusted URL lists regularly to prevent outbound data flows to expired or untrusted domains.
  • Deploy inline CNSF policy enforcement and real-time inspection to detect and block malicious prompt patterns entering cloud or SaaS workloads.
  • Strengthen internal East-West Traffic Security with microsegmentation and workload-to-workload flow controls to limit agentic AI lateral movement.
  • Integrate continuous Threat Detection and Anomaly Response for prompt identification of suspicious AI agent behaviors and rapid incident response.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image