The Register

Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing

PhishingHighphishing

Salesforce Agentforce contained three critical vulnerabilities allowing attackers to hijack AI agents, steal CRM data without user interaction, and send phishing messages. Zenity Labs discovered the flaws and Salesforce has patched them, but the incident highlights risks in AI-driven business applications.

AI summary · generated with Claude

https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958