Skip to content

SalesBleed: Zenity Labs to Reveal Zero-Click Salesforce Agentforce Data Exfiltration Flaws at AI Agent Security Summit 2026

Oct 07, 2026
Zenity | Secure AI Agents Everywhere
Article image for SalesBleed: Zenity Labs to Reveal Zero-Click Salesforce Agentforce Data Exfiltration Flaws at AI Agent Security Summit 2026

Summary

Security researchers are exposing SalesBleed, two zero-click Salesforce Agentforce vulnerabilities that allowed attackers to exfiltrate customer data by bypassing Salesforce's Trusted URLs boundary through DNS lookups and Slack link previews, with Zenity Labs researcher Tamir Ishay Sharbat presenting the findings October 21 at the AI Agent Security Summit 2026 at Pier Sixty in New York City, where Zenity will also disclose a CVSS 10.0 command injection flaw in a widely used official CI MCP server and a CVSS 8.3 DNS rebinding weakness exposing developers' local MCP servers to websites.

Key Points

  • Zenity hosts its AI Agent Security Summit 2026 in New York City on October 21 at Pier Sixty, with sessions covering agentic security threats and governance.
  • Zenity Labs' Tamir Ishay Sharbat will present SalesBleed, research showing two zero-click Salesforce Agentforce exfiltration paths that bypassed Salesforce's Trusted URLs boundary via DNS lookups and Slack link previews.
  • Research at the event includes a CVSS 10.0 command injection in a widely used official CI MCP server triggered by a fileName tool parameter, and a CVSS 8.3 DNS rebinding flaw letting websites reach developers' local MCP servers.

Tags

Read Original Article