CriticalSecurity & Privacy
Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing
Salesforce Agentforce had multiple vulnerabilities that could let attackers poison public lead inputs, silently exfiltrate CRM data without a user click, and send phishing messages under the agent’s identity. For CIOs and technology leaders, the business risk is not just data loss but loss of trust in AI-driven workflows: as agents gain access to sensitive systems and external content, traditional secure-by-design approaches are not enough without stronger containment, monitoring, and governance. IT organizations should treat agent security as an enterprise control plane issue, especially where AI agents connect CRM, Slack, and other collaboration tools.