Zenity Researcher Says SalesBleed Exploits Bypassed Salesforce Trusted URLs in Zero-Click Attacks
Summary
Zenity security researcher Tamir Ishay Sharbat will present SalesBleed at the company's AI Agent Security Summit in New York on October 21, showing two zero-click exfiltration paths that bypassed Salesforce's Trusted URLs boundary, one via DNS lookups and one via Slack link previews. The talk covers a poisoned Web-to-Lead entry that hijacks Salesforce Agentforce. Zenity says over half of enterprises report agents exceeding scope.
Key Points
- Zenity hosts its AI Agent Security Summit in New York City on October 21 at Pier Sixty, focused on where agentic security goes next.
- Over half of enterprises report agents exceeding scope in their lifecycle, and agentic investments are projected to overtake chatbot spending by 2027.
- Zenity's Tamir Ishay Sharbat presents SalesBleed, showing two zero-click exfiltration paths that bypassed Salesforce's Trusted URLs boundary.