AgentsThe story, in brief

Lab Exposes New Agentforce Data Exploit

Agentforce data breach needs no login. Zenity Labs found three chained vulnerabilities—Web-to-Lead form + DNS exfil—that bypass authentication entirely.

Illustration of independent geometric mechanisms passing paper tasks along branching amber tracks.
AI agents and the coordination of work.AI illustration by KeyNews
The KeyNews take

Why it matters

A critical agent security vulnerability in Salesforce's flagship agentic product exposes sensitive account data without user interaction or login. Practitioners deploying Agentforce in production need immediate clarity on patch status, affected versions, and compensating controls while this fix is pending.

The key facts

6 to know
  1. Three chained vulnerabilities in Agentforce identified by Zenity Labs (AI agent security provider)

  2. Attack path: Web-to-Lead form entry point + DNS query for data exfiltration

  3. No authentication or user interaction required

  4. Sensitive account data exposed

  5. Vulnerability disclosure source: Zenity Labs (independent cybersecurity research, not Salesforce advisory)

  6. Status: Article does not disclose patch status, timeline, affected versions, or CVSS score

Go to the source

Salesforce Bensalesforceben.com

Publisher excerpt: Cybersecurity experts discovered a way to pull sensitive account data from Agentforce without ever logging in or requiring the victim to click anything. A public Web-to-Lead form was used as the entry point, with a DNS query used as the exit. AI agent security provider Zenity Labs identified the…
Read original report
Back to today's editionMore agents news

Keep reading

Related stories

More from Agents