The Register covered our SalesBleed research 🙌🏼
Here's a quick recap:
Salesforce's Agentforce read a lead that an attacker submitted through a public form, and treated the text inside it as instructions. Since the agent already had access to the Accounts table, the injection didn't need to escalate anything to read it.
Its output guardrail, a URL redactor, was bypassed due to a vulnerability, and once the link was printed by the agent and rendered, a DNS lookup sent the data to the attacker's server with no click required from the user.
The same entry point also let the agent reply in Slack threads without requiring user confirmation and without indicating who invoked the agent, turning it into an anonymous phishing bot.
None of this required a misconfiguration. It was the default setup.
Salesforce has now fully fixed the issues.
https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958
Wiz Research 披露其自主运行的 Red Agent 在一家航空公司的公开 GraphQL 预订 API 中发现对象级授权失效(BOLA)漏洞,仅用一个根 URL、无种子数据和凭证,就在 15 分钟内映射后端架构并取得匿名会话。 该 API 使用连续整数标识符且下游解析器缺少后端角色校验,导致匿名的匿名网页角色即可读取跨度两年的乘客姓名、出生日期、账单地址、掩码信用卡号和实时航班行程,并能修改或删除活跃订单——contactsChange 篡改联系人邮箱劫持账户、flightDelete 静默取消航段、priceOverride 将票价归零、refundIssue/voidRefund 发起未经授权的退款。
Wiz Threat Research 在 LiteLLM、Flowise、LangChain、Langflow、ChromaDB、Ollama 等 AI 与 ML 服务上部署蜜罐,90 天遥测中观察到持续攻击,并将其归纳为三类模式:利用面向互联网的 MCP 服务器实现远程代码执行、针对 AI 智能体框架的盲提示注入,以及适配 AI 基础设施内部结构的后渗透。