The Containment Era is here. →Explore

Executive Summary

In September 2025, security researchers at Noma Security identified a critical vulnerability, termed ForcedLeak (CVSS 9.4), in Salesforce Agentforce, an AI-powered platform for constructing automation agents. The flaw allowed threat actors to launch indirect prompt injection attacks against Agentforce’s integration with Salesforce’s CRM, opening avenues for exfiltration of sensitive customer relationship data. The attack leveraged manipulated AI prompts that bypassed input validation, ultimately resulting in confidential business and customer information being at risk of exposure until Salesforce deployed a rapid patch.

This incident highlights the growing risks stemming from AI prompt injection vulnerabilities as more enterprises embrace AI-integrated SaaS for customer-facing processes. The Salesforce episode underscores regulatory and security urgency to address trust boundaries around rapidly-evolving AI within business-critical platforms.

Why This Matters Now

Prompt injection vulnerabilities in widely-used enterprise AI platforms like Salesforce Agentforce expose sensitive organizational data to novel attack paths. With increasing AI adoption in cloud applications and pressure to meet compliance mandates, urgent attention is required to proactively defend against abuse of generative AI integrations before attackers widely exploit these weaknesses.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Strong input validation, AI prompt sanitization, and continuous egress monitoring per NIST and PCI DSS could have limited data exposure through prompt injection.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust segmentation, east-west traffic security, policy-driven egress controls, and distributed visibility provided by CNSF capabilities could have detected, contained, or outright blocked malicious prompt injection exploitation, lateral expansion, and sensitive data leaks at multiple cloud kill chain stages.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Inline security fabric would have detected and policy-flagged suspicious AI-driven behaviors.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Microsegmentation would have limited agent access scope to only authorized datasets.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Monitored and restricted internal traffic, stopping unauthorized east-west traversal.

Command & Control

Control: Cloud Firewall (ACF) with Inline IPS

Mitigation: Inline detection and policy controls would flag/detect C2-like activity in outbound traffic.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Policy-driven egress filtering halts exfiltration attempts in real time.

Impact (Mitigations)

Centralized visibility enables rapid detection and incident response to limit overall impact.

Impact at a Glance

Affected Business Functions

  • Customer Relationship Management
  • Sales Operations
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive customer data from the CRM system due to unauthorized code execution.

Recommended Actions

  • Deploy east-west traffic segmentation and microsegmentation to strictly isolate AI agents and sensitive data stores.
  • Enforce granular, identity-based least privilege policies to prevent excessive access by AI workflows and applications.
  • Implement inline anomaly detection and distributed inspection for early detection of suspicious prompt injection and SaaS misuse behaviors.
  • Apply policy-driven egress controls, including FQDN and application-based filtering, to block unauthorized data egress channels.
  • Enhance centralized, cloud-native visibility and incident response orchestration to ensure rapid detection, investigation, and compliance actions.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image