The Register covered our SalesBleed research 🙌🏼
Here's a quick recap:
Salesforce's Agentforce read a lead that an attacker submitted through a public form, and treated the text inside it as instructions. Since the agent already had access to the Accounts table, the injection didn't need to escalate anything to read it.
Its output guardrail, a URL redactor, was bypassed due to a vulnerability, and once the link was printed by the agent and rendered, a DNS lookup sent the data to the attacker's server with no click required from the user.
The same entry point also let the agent reply in Slack threads without requiring user confirmation and without indicating who invoked the agent, turning it into an anonymous phishing bot.
None of this required a misconfiguration. It was the default setup.
Salesforce has now fully fixed the issues.
https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958
took a deep dive into Claude's new Chrome extension or should I say Agentic browser?
It introduces some interesting features and risks we haven't really seen in Atlas or Comet.
Zero-click prompt injection?
It's a half-click. That's @ben_nassi 's correction to his own use of the term, and on ep. 3 of In the Wild, From Dumbledore to Delayed Tool Invocation, he explains why the gap matters:
Mindgard 在 Amazon Kiro IDE 中发现一条数据外泄路径:攻击者控制的仓库内容被当作指令,诱导 Agent 读取本地敏感信息并写入 IDE 配置,最终由 IDE 自动发起网络请求把数据带出。测试针对 Windows 上的 Kiro IDE 0.7.45,在受信任与不受信任工作区中均复现。利用需要两步用户操作,即通过 File → Open Workspace From File 打开恶意工作区文件,然后向 Agent 发送任意消息,之后流程无需用户再要求 Kiro 访问或传输敏感数据,因此利用难度被评为低。Amazon 通过 HackerOne 验证了报告,并在 Kiro IDE 0.8.140 中修复;该提交获 40 美元 Amazon 商店礼品卡,CVE 资格仍在评估。
💥 Did you know that your agents can modify their own traces?
In our new paper, we show that Claude Code, Codex, Antigravity, Open Code, and Grok Build (but not Muse Code!) allow agents to easily modify or even delete their traces, without triggering any guardrails.
Modification and deletion can be done both by misaligned models or external attackers via prompt injections. We draw attention to this issue and suggest that traces should be much better protected than they are now!
安全研究者 Johann Rehberger 公开了对 Microsoft SQL Server Management Studio 中 AI 数据库助手 SQL Copilot 的研究,发现其中存在严重的提权路径,可从 SELECT 权限提升至 SYSADMIN。作者提醒用户确保 SSMS 安装已更新,并感谢 Microsoft 快速修补该问题,该研究还在两周前的 BlueHat Asia 上进行了展示。作者提到数据库 CONSTITUTION.md 这一概念,完整技术细节与视频演示见其博客文章。
面向 Claude Fable 5 的领域专属智能体红队测试!!
很快将登上排行榜:https://decodingtrust-agent.com/
引用Zhaorun Chen@zrrrr_cn
🚨 Claude Fable 5 JAILBROKEN.
We ran a quick security scan of Claude Fable 5 with Claude Code on our DecodingTrust-Agent Platform (https://decodingtrust-agent.com) and obtained 15%+ ASR with several high-severity failures😱🚨
Most concerningly, we found that Fable 5 appears very aggressive in financial-risk scenarios, sometimes directly executing transactions initiated from indirect prompt injections, without even confirming with the user!
Top 3 most severe attack trajectories we observed👇