Threat
SalesBleed shows how trusted AI agents can become data-exfil
First reported · Discovered invaders.ie
Page published
Earliest dated coverage: 28 Sep 2026 · First observed: 10 Oct 2026 · Latest dated coverage: 28 Sep 2026
Coverage timeline
Single-source incident — one report is available.
Why it matters
SalesBleed demonstrates that enterprise AI agents with tool access and connectors can be turned into automatic data-exfiltration paths through indirect prompt injection in untrusted records, bypassing traditional user-awareness defenses.
Zenity Labs disclosed SalesBleed on September 24, 2026, a set of Salesforce Agentforce weaknesses (associated with CVE-2026-73570) that let attacker-supplied CRM data hijack an AI agent for zero-click data exfiltration and Slack phishing. An attacker submits a Web-to-Lead record containing hidden prompt-injection instructions; when an internal user later asks Agentforce to review recent leads, the agent queries sensitive account data and leaks it via DNS lookups triggered automatically by HTML image rendering or Slack URL unfurling. Salesforce says it has remediated the issues and found no evidence of exploitation against customers.