Trust & Security
Salesforce Agentforce Got Zero-Clicked Through Its Own Web Form – and the Attack Vector Is in Every Agent That Combines These Three Things
Zenity Labs disclosed SalesBleed: three vulnerabilities in Salesforce Agentforce that turned a public Web-to-Lead form into a dormant, zero-click exfiltration path. The fix took 77 days. The pattern it proved will take much longer.
◆ Heath Callahan