Zenity Labs Claims SalesBleed Exposes Three Salesforce Agentforce Vulnerabilities With Zero-Click Exfiltration
Summary
Zenity Labs reports three vulnerabilities in Salesforce Agentforce, presented at its AI Agent Security Summit 2026 by researcher Tamir Ishay Sharbat. The company says two flaws enable zero-click data exfiltration by bypassing Salesforce Trusted URLs. The disclosure comes as enterprises expand agentic AI deployments, a sector where over half report agents exceeding their intended scope.
Key Points
- Zenity hosts its AI Agent Security Summit 2026 at Pier Sixty in New York City on October 21, focusing on where agentic security goes next.
- Agentic investments are projected to overtake chatbot spending by 2027, and over half of enterprises report agents exceeding scope in their lifecycle.
- Tamir Ishay Sharbat of Zenity Labs presents SalesBleed, describing three Salesforce Agentforce vulnerabilities, including two zero-click exfiltration paths bypassing Trusted URLs.