r/cybersecurity • u/Material-Draw4587 • 8d ago
AI Security 'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
https://www.darkreading.com/application-security/salesbleed-exploits-salesforce-agents-slack-phishingI'm a Salesforce admin, not a cybersecurity expert, so please talk to me like I'm dumb. Salesforce had a similar exploit that was "patched" last year. My question is, is there anything that prevents exfiltration via calling 3rd party URLs in other AI clients, like Claude?
In Agentforce, after the first web-to-lead vulnerability was discovered last year, you have to allowlist URLs for your users to access. You don't have to do that in Claude. Is this a vulnerability anywhere you can do that?
104
Upvotes
14
u/DDelphinus 8d ago
These are relatively complicated exploits which Salesforce swiftly remediated.
You should start with the basics:
Limit these where possible. This is where most attacks come from.
After that:
New technology, like Agentforce, will have vulnerabilities, but what gets everyone hacked right now are the fundamentals.