Tython

SalesforceSecurity

SalesBleed: The Trojan Lead Rides Again--and This Time It Phishes Your Slack

Scott Covert · 

When we first wrote about the trojan lead, the premise was simple: Web-to-Lead lets strangers write into your CRM, Agentforce reads what they wrote, and an agent can’t reliably tell data from instructions. This week Zenity Labs published “SalesBleed”–three Agentforce vulnerabilities that walked through that exact door again, this time all the way to zero-click CRM data theft and phishing messages sent under your agent’s own name. Salesforce has patched all three, and says it found no evidence of exploitation in the wild. But the research is worth your attention precisely because the entry point was the one we warned about: the trojan lead didn’t die, it upgraded.

The Three Flaws in Brief

  • Zero-click CRM exfiltration via Web-to-Lead. An attacker submits a lead whose fields contain hidden instructions. The payload sits dormant until an employee asks Agentforce about the lead; the agent then uses its own Query Records capability to pull data–including Account records–encodes the values into a subdomain of an attacker-controlled hostname, and returns it inside an HTML image tag. When the interface renders the image, DNS resolution alone leaks the data. The employee sees a normal-looking response. No one clicks anything.
  • The same exfiltration, through Slack. A variant abused Slack’s automatic link-preview (unfurling) mechanism: in affected configurations, a malicious URL surfaced by the agent triggered the preview fetch–and the exfiltration–without any recipient interaction at all.
  • Anonymous phishing under the agent’s identity. The default Slack Knowledge subagent template shipped with a “Reply to a Slack Thread” action that required no user confirmation and carried no attribution. An attacker–internal or external–could make the agent post phishing links to colleagues as itself, with no way for recipients to know who was really behind the message.

The load-bearing failure was Salesforce’s Trusted URLs mechanism, which is supposed to redact links and images pointing at untrusted destinations. Zenity found it didn’t register hostnames with unrecognized top-level domains, and that certain characters broke its URL parsing–two small gaps that, combined, let a crafted string sail past redaction.

Reported, Patched, and Still Your Problem

The disclosure timeline is genuinely good news: Zenity reported on June 1, Salesforce engaged within a day, the URL redaction bypass was fixed in mid-August, and Zenity confirmed all three issues resolved by September 21–including proper attribution and safer defaults for the Slack action. That’s the vendor side working as intended.

The reason this still belongs on your desk is that SalesBleed is not a bug so much as a category. Any agent that (1) reads records from untrusted external sources, (2) holds query access to sensitive data, and (3) can render rich content or take outbound actions is a latent exfiltration path. Salesforce closed these three routes; your org’s configuration decides how much any future route is worth.

Deeper Dive

The Anatomy: Why “Zero-Click” Is the Right Name

The classic phishing kill chain requires a victim to act–click the link, open the attachment, read out the code. SalesBleed required only that an employee do their job. Asking the agent “summarize this new lead” is the job. Everything after that–the query, the encoding, the image tag, the DNS lookup–happened inside the platform’s own machinery. That’s the structural shift agents introduce: the untrusted input and the privileged execution meet inside the agent’s context window, and no security awareness training touches what happens there. Your controls have to assume the injection eventually lands and constrain what it can do next.

Five Controls That Bound the Blast Radius

  1. Audit your Trusted URLs list now. Setup → Trusted URLs. The bypass is patched, but the control only helps if the allowlist is deliberate. Every entry is a destination your agents can be told to send data toward; treat additions with the same skepticism as a new Connected App.
  2. Re-check the agent user’s permissions. SalesBleed’s exfiltration reach was exactly the reach of the agent’s Query Records capability. An Agentforce agent runs as a user with a permission set–scope it to precisely the objects and fields its actions require. This is the same audit we prescribed for Claudeforce and AIforce; the agent identity is the guardrail.
  3. Treat Web-to-Lead and every other anonymous inbound channel as hostile. Web-to-Lead, Web-to-Case, Email-to-Case, and inbound integrations all write attacker-controllable content that agents later read. Where possible, keep freshly ingested, unreviewed records out of agent-accessible scope, and flag high-risk fields (free-text descriptions, comments) in your data classification.
  4. Require confirmation and attribution on outbound agent actions. The phishing flaw existed because a default action could message humans with no confirmation step and no record of the true invoker. Review every action attached to your agents–especially templates you adopted wholesale–and demand human-in-the-loop for anything that sends, posts, shares, or modifies outside the session.
  5. Monitor agent behavior like user behavior. Event Monitoring should answer: which agent queried what, on whose behalf, and what left the platform. Unusual query volume from an agent identity, or responses embedding external hostnames, are the SalesBleed signatures worth alerting on.

The Pattern Is the Point

Between the trojan lead research, this spring’s agent-related incidents, and now SalesBleed, the industry has demonstrated the same finding three different ways: agents inherit the platform’s trust without inheriting its judgment. Salesforce’s fixes narrowed the rendering and action gaps; the permission model, the inbound data hygiene, and the action governance remain configuration–which is to say, they remain yours. Zenity’s CTO put it well: the bigger lesson is what it takes to keep AI agents contained. Containment is not a patch you receive. It’s a posture you maintain.

Before You Go: Five Days to September 30

One more reminder, because the window is now five days: all Marketing Cloud Engagement client secrets that haven’t been rotated since March expire on September 30 under the new 180-day policy. After that, API calls fail authentication, triggered sends stop, web forms quietly stop adding subscribers, and nightly syncs skip without notification. We flagged this in last week’s Dreamforce recap; if the rotation is still on your to-do list, it’s now this week’s to-do list.

Book a 15-Minute Security Strategy Call

Reference(s):

https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958

https://labs.zenity.io/post/salesbleed-hijacking-agentforce-in-slack-for-anonymous-phishing

https://www.securityweek.com/salesbleed-flaws-in-salesforce-agentforce-enabled-zero-click-data-exfiltration/

https://www.infosecurity-magazine.com/news/vulnerabilities-salesforce-ai/

https://help.salesforce.com/s/articleView?id=005389124&language=en_US&type=1