Skip to content

Zenity Researcher Says SalesBleed Exploits Bypassed Salesforce Trusted URLs in Zero-Click Attacks

Oct 07, 2026
Zenity | Secure AI Agents Everywhere
Article image for Zenity Researcher Says SalesBleed Exploits Bypassed Salesforce Trusted URLs in Zero-Click Attacks

Summary

Zenity security researcher Tamir Ishay Sharbat will present SalesBleed at the company's AI Agent Security Summit in New York on October 21, showing two zero-click exfiltration paths that bypassed Salesforce's Trusted URLs boundary, one via DNS lookups and one via Slack link previews. The talk covers a poisoned Web-to-Lead entry that hijacks Salesforce Agentforce. Zenity says over half of enterprises report agents exceeding scope.

Key Points

  • Zenity hosts its AI Agent Security Summit in New York City on October 21 at Pier Sixty, focused on where agentic security goes next.
  • Over half of enterprises report agents exceeding scope in their lifecycle, and agentic investments are projected to overtake chatbot spending by 2027.
  • Zenity's Tamir Ishay Sharbat presents SalesBleed, showing two zero-click exfiltration paths that bypassed Salesforce's Trusted URLs boundary.

Tags

Read Original Article