
What happened
Zenity Labs published findings on September 24 detailing 'SalesBleed,' an attack chain that slipped hidden prompt injection payloads into public Web-to-Lead forms, hijacking Agentforce agents to quietly exfiltrate CRM data. Salesforce fixed the URL redaction bypass on August 18.
Why it matters
Any AI agent that ingests untrusted external records, renders links or images back to users, and holds sensitive tool permissions may face the same latent exfiltration path, Zenity researchers warned.
What to watch
The fixes apply to SalesBleed specifically, so the outcome hinges on whether other vendors' agents share the same three ingredients and how quickly they shore up prompt injection defenses.
WHO IT HITSEnterprise security teams running AI agents connected to CRM or similar record systems should review how those agents process externally submitted data and what backend permissions they hold, since the disclosed pattern is not unique to Salesforce Agentforce according to the researchers.
Summaries like this, in your inbox every morning.
Zenity Labs reported the vulnerabilities to Salesforce in June, giving the vendor roughly two months before Salesforce fully fixed the URL redaction bypass on August 18. The public disclosure, published September 24, comes after that remediation. The SalesBleed chain relied on three elements the researchers say sit together in many agent deployments: untrusted input via Web-to-Lead forms, an agent that treats record content as instructions and can render links or images, and backend tool permissions reaching sensitive data. The researchers demonstrated the risk by exfiltrating company names and deal sizes using DNS-based techniques that evaded Salesforce's Trusted URLs controls.
For readers outside security engineering, the significance is less about Salesforce specifically and more about a class of AI agents that are given access to both external inputs and sensitive internal systems. Zenity's report describes the payload as capable of querying anything a subagent's Query Records tool can reach, which in a typical General CRM deployment includes accounts and contacts. That breadth is what turns an otherwise ordinary record processing step into a potential exfiltration path.
Whether similar exposures are found elsewhere hinges on whether other agent platforms also combine externally submitted records, rich content rendering, and broad tool permissions without adequate separation. Organizations deploying such agents may need to examine which inputs are trusted and what data their agents can reach. The body does not specify what additional steps, if any, Salesforce or Zenity have planned beyond the August 18 fix.
For example, today's edition would include:
AI-summarized, only the topics you pick: one digest a day via Email, LINE, or Slack.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
Tamara Grant, who finished Purdue University's Master of Science in Artificial Intelligence in spring 2026, wa…

In a Sept. 25 letter, Walmart CEO John Furner said the retailer will not use AI, customers' income, shopping h…

Texas Instruments is trading around $278.05, above its $275.21 breakout level, and is testing resistance at $2…

Qualcomm introduced the Snapdragon 8 Elite Gen 6 and Elite Extreme Gen 6 chips with on-device AI, aiming at pr…

ASML trades around 31 times forward earnings and Applied Materials near 27 times, the article notes

CleanTechnica writer Fritz Hasler says Tesla's in-car Grok bot, Ara, offered an unprompted forecast that FSD V…
