#ForcedLeak
ForcedLeak flaw in Salesforce Agentforce exposes CRM data via Prompt Injection
ForcedLeak flaw in Salesforce Agentforce exposes CRM data via Prompt Injection
Experts disclosed a critical flaw, named ForcedLeak, in Salesforce Agentforce that enables indirect prompt injection, risking data exposure
securityaffairs.com
September 27, 2025 at 8:11 PM
SalesBleed: a web form hijacks Agentforce - zero-click CRM theft and Slack phishing. https://intel.threadlinqs.com/threat/TL-2026-2642 #ThreatIntel #Gozi #SalesBleed #ForcedLeak
September 25, 2026 at 3:24 AM
Critical #ForcedLeak flaw in Salesforce’s Agentforce AI agent exposed CRM data to remote attackers.

Read: hackread.com/forcedleak-s...

#CyberSecurity #Salesforce #Agentforce #Vulnerability #AI
ForcedLeak Flaw in Salesforce Agentforce AI Agent Exposed CRM Data
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
September 25, 2025 at 3:25 PM
This vuln is called "ForcedLeak", and let attackers smuggle AI-read instructions in via humble Web-to-Lead form... and ended up spilling data for the low, low price of five dollars. Double check what domains you have whitelisted folks!
October 2, 2025 at 11:41 AM
Critical Salesforce Vulnerability ‘ForcedLeak’ Exposes AI Agent Risks in AgentForce
ForcedLeak: Critical Salesforce AgentForce Vulnerability
ForcedLeak reveals how attackers exploited Salesforce AgentForce using prompt injection, exposing sensitive CRM data.
thecyberexpress.com
September 26, 2025 at 3:26 PM
"What color do you get by mixing red and yellow?"
ForcedLeak flaw in Salesforce Agentforce exposes CRM data via Prompt Injection
Experts disclosed a critical flaw, named ForcedLeak, in Salesforce Agentforce that enables indirect prompt injection, risking data exposure
securityaffairs.com
September 28, 2025 at 8:53 AM
Plus, we take a look at ITV's phone-hacking drama with David Tennant, and take a crack at decoding the history of the Rosetta Stone.

Hear all this and more in episode 437 of the "Smashing Security" podcast. Find it in all good podcast apps or at www.smashingsecurity.com/437

Enjoy!
437: Salesforce's trusted domain of doom
Researchers uncovered a security flaw in Salesforce’s shiny new Agentforce. The vulnerability, dubbed "ForcedLeak", let them smuggle AI-read instructions in via humble Web-to-Lead form... and ended up...
www.smashingsecurity.com
October 2, 2025 at 11:41 AM
Like any other tool, if you're using AI be aware of the risks. Malicious commands contained in the source material you use for your prompts may result in compromising yourself.

thehackernews.com/2025/09/sale...
Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection
ForcedLeak flaw in Salesforce Agentforce allows data exfiltration via indirect prompt injection; Salesforce issues patch.
thehackernews.com
September 26, 2025 at 4:07 PM
This is an important article highlighting the difference between AI and other injection vulnerabilities.

"..like saying that my house cat and a 650 pound wild tiger are the same because they’re both felines."
api.cyfluencer.com/s/what-s-the...
What’s the Difference Between AI Prompt Injection and XSS Vulnerabilities? - Noma Security
The ForcedLeak AI agent vulnerability raises the question, "What is the difference between AI prompt injection and XXS vulnerabilities?"
api.cyfluencer.com
October 14, 2025 at 11:51 AM
Critical vulnerability 'ForcedLeak' in Salesforce's Agentforce AI platform exposes sensitive CRM data. Organizations urged to apply patches and enhance security measures. #CyberSecurity #Salesforce #DataBreach Link: thedailytechfeed.com/critical-vul...
September 26, 2025 at 4:29 PM
Notícia da SecurityWeek

"Salesforce AI Hack Enabled CRM Data Theft" #bolhasec
Salesforce AI Hack Enabled CRM Data Theft
Prompt injection has been leveraged alongside an expired domain to steal Salesforce data in an attack named ForcedLeak.
www.securityweek.com
September 28, 2025 at 5:30 PM
ИИ-хак Salesforce позволил украсть данные CRM

В атаке под названием ForcedLeak использовалась инъекция запросов вместе с истекшим доменом для кражи данных Salesforce.

#ai #news
Salesforce AI Hack Enabled CRM Data Theft
www.securityweek.com
September 26, 2025 at 9:38 PM
Salesforce’s trusted domain of doom • Graham Cluley

Researchers uncovered a security flaw in Salesforce’s shiny new Agentforce. The vulnerability, dubbed “ForcedLeak”, let them smuggle AI-read instructions in via humble Web-to-Lead form… and ended up spilling data for the low, low price of five…
Salesforce’s trusted domain of doom • Graham Cluley
Researchers uncovered a security flaw in Salesforce’s shiny new Agentforce. The vulnerability, dubbed “ForcedLeak”, let them smuggle AI-read instructions in via humble Web-to-Lead form… and ended up spilling data for the low, low price of five dollars. And we discuss why data breach communicationss still default to “we take security seriously” while quietly implying “assume no breach” – until the inevitable walk-back.
nexttech-news.com
October 2, 2025 at 6:35 AM
Do not give AI Agents more permissions than you would give frontline level 1 agents, ever! (and audit the hell out of their usage/access patterns) #Infosec beyondmachines.net/event_detail...
Critical flaw in Salesforce Agentforce enables data exfiltration through AI agent exploitation
Researchers discovered a critical vulnerability called ForcedLeak (CVE-pending) in Salesforce Agentforce that allows attackers to exploit AI agents through indirect prompt injection attacks via Web-to...
beyondmachines.net
September 30, 2025 at 5:21 PM
Full story 👉 www.technadu.com/forcedleak-v...

👉 What guardrails do you think are essential to prevent prompt injection at scale? Drop your thoughts below.

#CyberSecurity #AIsecurity #Salesforce
ForcedLeak Vulnerability in Salesforce Agentforce Exposed CRM Data Through Indirect AI Prompt Injection
The ForcedLeak vulnerability, a critical flaw in Salesforce Agentforce, allowed for data exfiltration via AI prompt injection attacks.
www.technadu.com
September 26, 2025 at 6:58 AM
⚠️ ForcedLeak: CVSS 9.4 vuln in Salesforce Agentforce exposed CRM data via AI prompt injection.
🔹 Attackers used expired whitelisted domain
🔹 Salesforce patched w/ Trusted URLs
🔹 Experts warn AI agents need stronger guardrails

#AIsecurity #Salesforce #CyberSecurity
September 26, 2025 at 6:56 AM
ForcedLeak: AI Agent risks exposed in Salesforce AgentForce. simonwillison.net
September 26, 2025 at 11:38 PM
Vulnerabilidade em plataforma de IA da Salesforce expôs dados de clientes
Uma vulnerabilidade de segurança crítica no sistema Agentforce da Salesforce expôs informações confidenciais de clientes da companhia, conforme revelou a Noma Security na quinta-feira (25). Ela **permitia que invasores roubassem esses conteúdos por meio de injeção indireta de prompt**. Denominada “ForcedLeak”, a falha mostra como ferramentas de negócios integradas a soluções de inteligência artificial sem supervisão humana podem ser usadas indevidamente para a coleta de dados, de acordo com a empresa de segurança cibernética que descobriu o problema. Não se sabe se a brecha foi explorada em ataques. A falha afetava a plataforma AgentForce. (Imagem: Salesforce/Divulgação) ## Instruções maliciosas para agentes de IA O recurso Agentforce é uma plataforma de agentes de inteligência artificial, bots com capacidade de realizar atividades de maneira autônoma. Segundo o relatório, cibercriminosos poderiam aproveitar a solução para acessar dados de usuários a partir de prompts maliciosos ou permissões mal configuradas. * Para tanto, **invasores usariam formulários da plataforma para enviar instruções aos agentes, escondidas em meio a dados que a IA já processa normalmente** ; * Ao ler solicitações feitas por clientes legítimos, o sistema também analisaria os pedidos maliciosos incorporados, sem distingui-los dos demais, realizando a tarefa desejada; * Em um teste feito por pesquisadores da Noma, a IA enviou endereços de email de clientes para um servidor externo, obedecendo as instruções e confirmando o sucesso do ataque; * Os especialistas disseram que, em uma campanha real, seria possível coletar diversos dados sigilosos de terceiros, incluindo contratos, relatórios de venda, estratégias de negócios, comunicações internas e muito mais. A operação envolvia, ainda, a utilização de um domínio considerado “confiável” pela Salesforce, para o qual os dados extraviados foram enviados. Curiosamente, ele estava expirado e à venda por apenas US$ 5, o equivalente a R$ 26,70 pela cotação do dia, valor pago pelos pesquisadores. Qualquer empresa que utilizasse o Agentforce com os formulários Web-toLead habilitado, principalmente para vendas, marketing e aquisição de clientes, era uma vítima em potencial. A exploração da vulnerabilidade ForcedLeak poderia trazer sérios impactos para os alvos, segundo o estudo. Os agentes de IA são bots com capacidade autônoma. (Imagem: Getty Images) ## Correções implementadas Alertada em julho sobre a falha na plataforma Agentforce, a Salesforce implementou as correções necessárias no início de setembro. Entre elas, a empresa lançou **patches que impedem o envio de dados pelos agentes de IA para endereços não confiáveis**. “O cenário de segurança para injeção imediata continua sendo uma área complexa e em evolução, e continuamos a investir em fortes controles de segurança e trabalhar em estreita colaboração com a comunidade de pesquisa para ajudar a proteger nossos clientes à medida que esses tipos de problemas surgem”, ressaltou a companhia, em comunicado ao site _Hackread_. Fornecedora de milhares de organizações em todo o mundo, a Salesforce foi alvo de um incidente de segurança recentemente, chatbot usado para vendas e engajamento. A violação atingiu grandes clientes da marca, como Google, Adidas, Allianz Life e Palo Alto Networks, cujas informações acabaram vazando. Gostou do conteúdo? Siga no TecMundo para mais atualizações sobre cibersegurança e compartilhe as notícias nas redes sociais.
www.tecmundo.com.br
September 27, 2025 at 1:30 AM
Salesforce’s trusted domain of doom • Graham Cluley

Researchers uncovered a security flaw in Salesforce’s shiny new Agentforce. The vulnerability, dubbed “ForcedLeak”, let them smuggle AI-read instructions in via humble Web-to-Lead form… and ended up spilling data for the low, low price of five…
Salesforce’s trusted domain of doom • Graham Cluley
Researchers uncovered a security flaw in Salesforce’s shiny new Agentforce. The vulnerability, dubbed “ForcedLeak”, let them smuggle AI-read instructions in via humble Web-to-Lead form… and ended up spilling data for the low, low price of five dollars. And we discuss why data breach communicationss still default to “we take security seriously” while quietly implying “assume no breach” – until the inevitable walk-back.
nexttech-news.com
October 2, 2025 at 6:35 AM
ForcedLeak flaw in Salesforce Agentforce exposes CRM data via Prompt Injection Researchers disclosed a critical flaw, named ForcedLeak, in Salesforce Agentforce that enables indirect prompt injecti...

#Breaking #newsef="/hashtag/News" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#News #hacking"/hashtag/Hacking" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#Hacking #security/hashtag/Security" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#Security #AI #ForcedLeak […]

[Original post on securityaffairs.com]
September 27, 2025 at 9:56 PM
Vulnerability in Salesforce AI could be tricked into leaking CRM data
A newly disclosed critical vulnerability in Salesforce’s Agentforce platform could trick the AI agent into leaking sensitive CRM data through indirect prompt injection. Researchers at Noma Security, who identified the bug dubbed “ForcedLeak,” said in a blog post shared with CSO ahead of its publication on Thursday that it could be exploited by attackers inserting malicious instructions into a routine customer form. Salesforce patched the issue after disclosure, but Noma researchers believe the implications go well beyond one bug. ## From innocent Form to full-on data heist The attack path revealed by Noma was deceptively simple. By planting malicious text inside Salesforce’s Web-to-Lead form, commonly used in marketing campaigns, researchers found that an AI agent (Agentforce) tasked with reviewing submissions could be coaxed into running instructions it was never meant to. The description field, with its 42000-character allowance, provided enough space to hide multi-step payloads disguised as harmless business requests. Once an employee interacts with the data and asks Agentforce to process it, the system obediently carries out both the real request and the attacker’s hidden script. Worse, Salesforce’s content security policy included an expired domain still on its whitelist. By re-registering the domain for just $5, researchers created a trusted-looking data exfiltration channel, turning a minor oversight into a major security hole. “Indirect Prompt Injection is basically cross-site scripting, but instead of tricking a database, attackers get inline AI to do it,” said Andy Bennet, CISO at Apollo Information Systems. “It’s like a mix of scripted attacks and social engineering. The innovation is impressive and the impacts are potentially staggering.” Salesforce apparently patched this CVE-pending flaw on September 8, 2025, by enforcing “Trusted URL allowlists” for Agentforce. While the company did not directly credit Noma for the finding, it included a related description. “Our underlying services powering Agentforce will enforce the Trusted URL allowlist to ensure no malicious links are called or generated through potential prompt injection,” it had said. Salesforce did not immediately respond to a CSO’s request for comment on Noma’s disclosure. ## Guardrails, not just patches While Salesforce responded quickly with a patch, experts agree that AI agents represent a fundamentally broader attack surface. These systems combine memory, decision-making, and tool execution, meaning compromises can spread quickly and, as Bennet puts it, “at machine speed.” “It’s advisable to secure the systems around the AI agents in use, which include APIs, forms, and middleware, so that prompt injection is harder to exploit and less harmful if it succeeds,” said Chrissa Constantine, senior cybersecurity solution architect at Black Duck. She emphasized that true prevention requires not just patching but “maintaining configuration and establishing guardrails around the agent design, software supply chain, web application, and API testing.” Noma’s researchers echoed that call, urging organizations to treat AI agents like production systems, inventorying every agent, validating outbound connections, sanitizing inputs before they reach the model, and flagging any sensitive data access or internet egress. Sanitize external input before the agent sees it, suggested Elad Luz, head of research at Oasis Security. “Treat free-text from contact forms as untrusted input. Use an input mediation layer to extract only expected fields, strip/neutralize instructions, links, and markup, and prevent the model from interpreting user content as commands (prompt-injection resilience).” 1.
www.csoonline.com
September 25, 2025 at 1:24 PM
New “ForcedLeak” shows how a simple form field can hijack Salesforce Agentforce and exfiltrate leads. CVSS 9.4 isn’t a warning; it’s a fire alarm.
https://f.mtr.cool/enkvzfimlb
March 10, 2026 at 4:13 PM