SalesBleed: What a Hidden Prompt in an Enquiry Form Did to Salesforce's AI Agent
This story is from 2026-10-01. It is preserved in the archive; the latest stories are on the live feed.
TL;DR Security researchers at Zenity Labs disclosed zero-click vulnerabilities in Salesforce Agentforce, published 24 September 2026, under the name SalesBleed. An attacker could plant hidden instructions inside a public Web-to-Lead form. No login, no click from anyone inside the business was requi…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-10-01 23:07 · DEV Community — AI
SalesBleed: What a Hidden Prompt in an Enquiry Form Did to Salesforce's AI Agent
More stories
- Bring near-Astra intelligence to everyday work with GPT-6.1 Sol on Amazon Bedrock — AWS Machine Learning Blog
- Gemini 4 Argon: our next era of frontier intelligence — Google Gemini Blog
- Introducing Olmo-core 3: Open, scalable training infrastructure for large MoEs — Allen Institute for AI (Ai2)
- Google Releases New Gemini Model With Guardrails Amid A.I. Safety Debate — New York Times Technology
- OpenAI Says It Will Not Release Newest Astra A.I. Model Over Safety Concerns — New York Times Technology
- OpenAI DevDay 2026 Keynote (FULL) — OpenAI YouTube
- Introducing GPT-6.1 Sol — OpenAI News
- OpenAI’s Dots Are Always-On AI Agents—and Its Answer to Meta’s Muse — Wired AI
Get the daily brief of stories like this at 6:30 every morning →