The Hacker News 介绍研究者提出的 Agent Data Injection(ADI):攻击者操纵智能体依赖的数据字段,使其在继续执行原任务时依据错误信息采取行动,而不是直接插入新的操作指令。作者在网页操作和编码助手等受控场景中展示了错误点击、误信身份或执行记录等风险,并报告部分针对传统提示注入的防御无法同样阻断这类数据操纵。不同产品和界面设计的结果存在差异,例如随机化元素标识可限制某类点击攻击;更严格的数据来源追踪也伴随任务完成能力下降。报道基于研究者实验及访谈,不代表存在已确认的在野利用,也不能将单项防御结果泛化为全面安全。
The Register covered our SalesBleed research 🙌🏼
Here's a quick recap:
Salesforce's Agentforce read a lead that an attacker submitted through a public form, and treated the text inside it as instructions. Since the agent already had access to the Accounts table, the injection didn't need to escalate anything to read it.
Its output guardrail, a URL redactor, was bypassed due to a vulnerability, and once the link was printed by the agent and rendered, a DNS lookup sent the data to the attacker's server with no click required from the user.
The same entry point also let the agent reply in Slack threads without requiring user confirmation and without indicating who invoked the agent, turning it into an anonymous phishing bot.
None of this required a misconfiguration. It was the default setup.
Salesforce has now fully fixed the issues.
https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958