Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing

Salesforce Agentforce had multiple vulnerabilities that could let attackers poison public lead inputs, silently exfiltrate CRM data without a user click, and send phishing messages under the agent’s identity. For CIOs and technology leaders, the business risk is not just data loss but loss of trust in AI-driven workflows: as agents gain access to sensitive systems and external content, traditional secure-by-design approaches are not enough without stronger containment, monitoring, and governance. IT organizations should treat agent security as an enterprise control plane issue, especially where AI agents connect CRM, Slack, and other collaboration tools.

Michael BarguryThe Register4 min read
Read full article
Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing

Read the full story at The Register →