การยินยอมใช้คุกกี้

COOKIE CONSENT

เราใช้คุกกี้เพื่อปรับปรุงประสบการณ์การใช้งาน วิเคราะห์การเข้าใช้เว็บไซต์ และนำเสนอเนื้อหาที่เกี่ยวข้อง ท่านสามารถเลือกประเภทคุกกี้ที่ยินยอมได้ ดูรายละเอียดเพิ่มเติมใน ประกาศคุกกี้

Application Security

SalesBleed Vulnerability Exposes Salesforce Agentforce to Data Theft

FORTSECURE GLOBAL· 2026-09-25🛰 The Register - Security
#Application Security#Data Breach#Salesforce#Cloud Security
SalesBleed Vulnerability Exposes Salesforce Agentforce to Data Theft

Critical security flaws dubbed 'SalesBleed' have been discovered in Salesforce Agentforce, potentially enabling unauthorized CRM data theft and silent phishing.

Understanding the 'SalesBleed' Vulnerability. Security researchers have identified critical weaknesses in the Salesforce Agentforce platform that could allow unauthorized actors to execute 0-click data extraction and deploy anonymous phishing campaigns. The flaw, nicknamed 'SalesBleed,' exploits the way the platform handles agent interactions, leading to severe consequences for data privacy and integrity within the CRM environment. Because these agents are designed to interact with sensitive data, the potential for mass unauthorized information disclosure is significant if left unpatched. ## Critical Security Best Practices. Organizations utilizing Salesforce must prioritize the following actions: Immediately review your Salesforce Agentforce configuration logs for any unusual activity or unrecognized access tokens. Apply all security patches released by Salesforce as soon as they become available. Additionally, implement strict multi-factor authentication (MFA) and restrict agent-to-agent communication permissions to ensure that even if a vulnerability is exploited, the impact is contained. Proactive auditing of CRM-integrated third-party applications is essential to maintain the confidentiality and integrity of your corporate data against evolving platform-specific threats.


แหล่งที่มา: The Register - Security เผยแพร่ครั้งแรก: Thu, 24 Sep 2026 21:01:15 +0200 บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: The Register - Security

เผยแพร่ครั้งแรก: Thu, 24 Sep 2026 21:01:15 +0200

บทความต้นฉบับ: https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958

อ่านบทความต้นฉบับ ↗
ถูกใจบทความนี้

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog