SalesBleed: How zero-click flaws in Salesforce Agentforce let attackers siphon CRM data
Zenity Labs disclosed a zero-click attack chain against Salesforce Agentforce that used poisoned Web-to-Lead submissions, prompt injection, and DNS exfiltration to extract CRM fields without authentication. Salesforce patched the immediate vulnerability; the underlying agent-risk pattern remains relevant for other deployments.



