CyberHighReportedAccelerating
7.7
AI-Driven Attack Campaign Hits Hundreds of Online Retailers
SecurityWeekLO·2 days ago
Researchers disclosed three vulnerabilities in Salesforce Agentforce, a low-code AI agent platform, that could allow attackers to hijack trusted agents, exfiltrate data, and launch phishing campaigns without user interaction. The flaws, dubbed 'SalesBleed,' are unpatched as of publication, and exploitation could compromise enterprise data across Salesforce deployments. This is a notable supply-chain risk given Agentforce's integration into enterprise workflows.
Entities