Informa TechTarget
|
Cybersecurity Dive
InformationWeek
Channel Dive
TechTarget:网络安全
探索我们的品牌
Dark Reading 资源库
Black Hat 新闻
Omdia 网络安全
广告合作
通讯订阅
网络安全主题
全球视野
The Edge
DR Technology
活动
资源
应用安全
端点安全
漏洞与威胁
网络风险
新闻
“Salesbleed”利用 Salesforce Agent 实现 Slack 网络钓鱼
Agentic AI 可以将任意指令从 Web 跨越多款应用程序, smuggle(走私/潜入)到受信任的内部通信渠道中。
Nate Nelson,特约撰稿人
2026年9月25日
6分钟阅读
来源:IGOR MILLER 通过 GETTY IMAGES 提供
Salesforce Agentforce 中的漏洞被研究人员统称为“Salesbleed”,可能暴露客户的内部数据,更糟糕的是,允许攻击者从受信任的公司渠道内部对员工进行网络钓鱼。
正如那些令客户和投资者兴奋的强大且相互关联的 AI 平台所常发生的那样,安全性和可见性仍然是难以解决的难题。Zenity 的研究人员指出,Agentforce 中的三个“Salesbleed”弱点允许黑客通过 Web-to-lead(网页到潜在客户)表单缓慢地从受害者那里窃取数据。然而,最有趣的发现在于,这种看似微不足道的 Web-to-lead 漏洞如何与正常的 Agentforce 工作流相结合,最终在员工最信任的 Slack 渠道内部实现网络钓鱼。
基于 Salesforce Web-to-Lead 表单的问题
一年前,Noma Security 的研究人员揭示了一种利用 Salesforce 窃取企业数据的巧妙方法。这一技巧始于 Web-to-lead 表单:这是互联网上少数几个公司愿意接受来自随机个人的近乎任意数据的情境之一。本质上,销售潜在客户会填写注册表单以获取访问权限,然后这些数据会被导入 Salesforce。在过去,攻击者可能会利用 Web-to-lead 表单发送恶意代码。在这些 Agentic(代理式)时代,研究人员认为他们可以发送恶意提示(prompts)。
相关:提示注入漏洞击中了价值40亿美元的Agentic AI应用“Manus”
如果攻击者假设其目标正在运行 Agentforce AI 代理,那么事实证明,他们可以在 Web-to-lead 表单中植入一个特别构造的 AI 指令——例如,将数据窃取到攻击者控制的 URL 的指令。交互另一端的代理将摄取并处理该指令,并在受害者公司的环境中执行请求。Salesforce 对 Noma 的发现做出了回应,迅速完善了其关于攻击者可能用于此类攻击的 URL 的规则。当时 Dark Reading 指出,“然而,对其 AI 处理指令方式的结构性修复目前仍然难以捉摸。”
这种创可贴式的方法未能治疗根本感染,而现在,一年后,来自 Zenity 的一组新研究人员发现,他们可以使用简单的变通方法来绕过 Salesforce 针对去年发现而实施的 URL 过滤规则,从而执行大致相同的攻击。
研究人员强调了其攻击的便利性。一方面,没有任何方法可以识别、暂停或以其他方式惩罚使用 Web-to-lead 表单的过往互联网作恶者。而且,通过让 AI 代理为他们效劳,攻击者可以轻松搭便车,利用 Salesforce 客户通常授予其机器人的健康权限。
相关:GitLab 电子邮件地址可被武器化用于供应链攻击
通过 Salesforce Agent 利用 Slack
Zenity 的漏洞利用程序只有一个缺点:对于任何给定的提示,攻击者只能窃取能够容纳在一个子域名字符串中的数据量。这几乎不足以造成重大损害,除非攻击者在寻找非常精确的数据,或者自动化了数百或数千个恶意请求。
但读取和发送数据只是 Agentforce 代理所拥有的众多能力中的两项。如果代理能为合法用户完成一千零一件其他事情,它们是否也能对攻击者做同样的事?
例如,用户可以直接将 Salesforce 代理部署到 Slack 中。Slack 代理可以被分配各种权限,以“子代理”的形式存在,允许其读取或写入数据。为确保它们不会执行意外操作,可以配置代理要求先获得用户确认。这些代理还内置了溯源功能,能够识别对特定代理行为负责的人类用户。
然而,在代理回复 Slack 线程的能力方面,却缺乏这些控制措施。Zenity 的研究人员认为,如果外部攻击者能够将恶意提示注入 Web-to-lead 表单,那么该指令不仅可以用于窃取数据,还可以诱导 Salesforce 机器人回复公司内部 Slack 线程,而没有任何机制能阻止这一行为。这条消息可能包含社会工程学元素,利用前面提到的 Salesforce 受信任 URL 保护中的漏洞来投放钓鱼链接。由于缺乏溯源信息,这条消息看起来就像是由真实员工或 IT 帮助台发送的。在受信任的内部通讯渠道中,很可能没人会怀疑其恶意意图。
相关文章:AI 代理如何引发企业失控成本
Salesforce 加固 Agentforce 以防范网络钓鱼
Salesforce 在向 Dark Reading 发表的声明中承认了这些漏洞(它们没有 CVE 编号),并指出目前没有证据表明真实攻击者已利用这些漏洞。该公司表示:“我们已更新 Slack 中某些 Agentforce 操作的默认设置,要求在发送消息之前需要用户确认,并且[正在]与客户直接沟通,帮助他们审查配置并进行推荐更改。”
该公司还承认,其对去年 Web-to-lead 漏洞的响应只是快速修复,而非全面解决方案。此次,它实施了自认为更稳健的解决方案。
此前,Salesforce 的 URL 脱敏控制依赖于正则表达式(regex)匹配来识别 AI 代理输出中的不受信任 URL。本质上,它检查一段文本是否看起来像 URL,这使得研究人员能够通过意想不到的格式隐藏其域名。该公司表示,现在它使用符合规范的 URL 解析,更实质性地分解和解释潜在 URL 字符串指向何处。
除了彻底改造的 URL 解析系统外,Salesforce 还在整合其 URL 检查流程。此前,代理工作流的不同部分可能会分别对 URL 采取行动,而现在所有与 URL 相关的 AI 流量都被引导至单一网关,该网关应用更一致的检查和安全规则。
深层问题困扰代理技术
时间将证明研究人员是否会再次破解 Salesforce 的修复措施。正如 Zenity 的分析人员指出的那样,代理平台存在更多 URL 策略无法涵盖的结构弱点。
“我们多年来一直在说:你赋予代理的权力越大,它们就越危险。”Zenity 安全研究总监 Tamir Ishay Sharbat 表示。“一旦代理拥有自行向多个频道发送消息的能力,例如,它就变成了可以被滥用的东西。当你让它们同时访问敏感信息——你的应付账款、潜在客户、合同等——以及外部渠道[如 Web-to-lead 表单]时,这种组合非常危险。”
除了这种危险的组合之外,代理还存在可见性问题。
“当你购买企业软件时,你会理所当然地认为它会有日志——也就是说,它能清楚地了解谁做了什么以及为什么这样做。”Zenity首席技术官迈克尔·巴格瑞(Michael Bargury)指出。“而对于智能体而言,由于大家都在快速构建,整个市场都在打造黑盒。这使得它们更难让人信任。”
“你无法查看其推理过程,也无法看到它在幕后做了什么——你只能得到摘要。”巴格瑞 lament 道。“这不仅仅是Salesforce的问题;这是整个行业普遍存在的问题。”
关于作者
内特·纳尔逊(Nate Nelson)
特约撰稿人
内特·纳尔逊是一名记者和屡获殊荣的脚本作家。除了为Dark Reading撰稿外,他还为网络安全领域最受欢迎的播客节目《Darknet Diaries》撰稿。
他职业生涯始于自由撰稿人,为科技和金融界的高管代笔撰写福布斯(Forbes)和CNBC的评论文章。随后,他转型进入新闻业,在Threatpost工作,报道网络安全新闻和趋势。在那些年间,他共同创建了网络安全播客《Malicious Life》,该节目曾登上苹果播客(Apple Podcasts)和Spotify技术类播客排行榜前20名。
他拥有纽约大学(New York University)和巴德学院(Bard College)的学位。作为一名土生土长的纽约人,他拥有一种优越感,但他足够礼貌,将其深藏心底。
希望更多Dark Reading的文章出现在你的Google搜索结果中?
立即添加我们
更多洞察
行业报告
云安全现状:最新挑战
组织如何管理事件响应
企业如何开发安全应用
RSAC 2026内幕:安全领袖揭示重塑防御策略的风险
来自Black Hat USA 2025的关键新闻与洞察
获取更多研究
网络研讨会
有效的警报分类:减少噪音并发现真实威胁
2027年网络安全展望
威胁暴露分析:衡量和传达安全风险
基准分数是一个虚假信号
构建高效的红队:超越渗透测试
更多网络研讨会
你可能也喜欢
应用安全
供应链攻击秘密为Cline用户安装OpenClaw
作者:Rob Wright
2026年2月19日
应用安全
中国黑客劫持Notepad++更新长达6个月
作者:Jai Vijayan
2026年2月2日
应用安全
特朗普政府撤销拜登时代的软件指导方针
作者:Alexander Culafi
2026年1月29日
应用安全
微软在“补丁星期二”轻量级更新中修复了被利用的零日漏洞
作者:Jai Vijayan
2025年12月9日
精选
查看Black Hat USA 2026大会指南,获取来自该展会及关于该展会的报道和情报!
编辑精选
网络风险
Anthropic首席执行官:是时候从改进AI转向控制AI了
作者:Elizabeth Montalbano
2026年9月14日
6分钟阅读
网络风险
为什么AI在欺骗人类方面如此擅长
2026年9月11日
漏洞与威胁
“补丁星期二”再破纪录,发布974个CVE
作者:Jai Vijayan
2026年9月8日
5分钟阅读
希望更多Dark Reading的文章出现在你的Google搜索结果中?
2026年11月12日 | 虚拟活动
在AI时代,每个企业都应了解的云资产安全须知
保留您的席位
紧跟最新的网络安全威胁、新发现的漏洞、数据泄露信息和新兴趋势。每日或每周直接发送至您的电子邮箱。
订阅
发现更多
Black Hat
Omdia
与我们合作
关于我们
认识编辑团队
广告合作
reprint(重印)
加入我们
新闻通讯注册
关注我们
版权所有 © 2026 TechTarget, Inc. d/b/a Informa TechTarget。本网站由Informa TechTarget拥有并运营,它是全球网络的一部分,旨在告知、影响和连接全球的技术买家和卖家。所有版权均归其所有。Informa PLC的注册办公室位于5 Howick Place, London SW1P 1WG。在英格兰和威尔士注册。TechTarget, Inc.的注册办公室位于275 Grove St. Newton, MA 02466。
首页|
Cookie政策|
隐私权|
使用条款
您的隐私选择
Informa TechTarget
|
Cybersecurity Dive
InformationWeek
Channel Dive
TechTarget: Cybersecurity
Explore our brands
Dark Reading Resource Library
Black Hat News
Omdia Cybersecurity
Advertise
NEWSLETTER SIGN-UP
Cybersecurity Topics
World
The Edge
DR Technology
Events
Resources
APPLICATION SECURITY
ENDPOINT SECURITY
VULNERABILITIES & THREATS
CYBER RISK
NEWS
'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
Agentic AI can smuggle arbitrary instructions from the Web, across multiple apps, into trusted internal communications channels.
Nate Nelson,Contributing Writer
September 25, 2026
6 Min Read
SOURCE: IGOR MILLER VIA GETTY IMAGES
Vulnerabilities in Salesforce Agentforce, collectively dubbed "Salesbleed" by researchers, could expose customers' internal data and, worse, allow attackers to phish employees from within trusted company channels.
As so often happens with powerful, interconnected AI platforms that excite customers and investors, security and visibility remain hard problems to solve. Researchers at Zenity noted that the three "Salesbleed" weaknesses in Agentforce allow hackers to slowly bleed data from victims via Web-to-lead forms. The most interesting finding, though, is how this seemingly modest Web-to-lead vulnerability can be combined with normal Agentforce workflows to ultimately phish employees from within their most trusted Slack channels.
Building on Issues With Salesforce Web-to-Lead Forms
One year ago, researchers at Noma Security revealed a neat little way to steal corporate data using Salesforce. The trick began with Web-to-lead forms: one of the few contexts on the Internet in which companies will willingly accept near-arbitrary data sent by random individuals. Essentially, sales prospects fill out a registration form to gain access to something, and that lead data is then imported to Salesforce. In the past, attackers might have used Web-to-lead forms to send malicious code. In these agentic days, the researchers figured they could send malicious prompts.
Related:Prompt-Injection Bug Hits $4B Agentic AI App 'Manus'
If an attacker presumed that their target was running Agentforce AI agents, it turned out that they could plant a specially crafted AI instruction — for example, an instruction to exfiltrate data to an attacker-controlled URL — in a Web-to-lead form. An agent on the other end of the interaction would ingest and process the instruction, and execute the request inside of the victim company's environment. Salesforce responded to Noma's findings by quickly polishing its rules around URLs that an attacker might use to carry out such an attack. Dark Reading noted at the time that "structural fixes to how its AI processes instructions however remain elusive for now."
This Band-Aid failed to treat the underlying infection, and now, a year later, a new set of researchers from Zenity found that they could perform largely the same attack, using simple workarounds to the URL filtering rules Salesforce implemented in response to last year's findings.
The researchers stressed how convenient their attack was. For one thing, there's no way to identify, suspend, or in any other way punish any passing Internet miscreant using Web-to-lead forms. And by having an AI agent do their bidding for them, attackers can effortlessly piggyback on the typically healthy permissions Salesforce customers willingly grant their bots.
Related:GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks
Exploiting Slack via Salesforce Agents
There was just one shortcoming in Zenity's exploit: For any given prompt, an attacker could exfiltrate only as much data as would fit into one subdomain string. That's hardly enough to cause much damage, unless the attacker were looking for very precise data, or automated hundreds or thousands of malicious requests.
But reading and sending data are only two among many powers afforded to Agentforce agents. If agents can do a thousand and one other things for legitimate users, could they do those same things for an attacker?
For example, users can deploy Salesforce agents directly to Slack. Slack agents can be assigned various permissions, in the form of "subagents," which allow them to read or write data. To ensure that they don't perform unwanted actions, agents can be configured to require user confirmation first. They also come with built-in attribution, identifying the human user responsible for a particular agentic action.
However, these controls were missing when it came to an agent's ability to reply to a Slack thread. Zenity researchers reasoned that if an external attacker could inject a malicious prompt into a Web-to-lead form, instead of just exfiltrating data, the instruction could induce a Salesforce bot to reply to an internal company Slack thread, and nothing would stop them from doing it. The message could incorporate social engineering, with a phishing link leveraging those previously described gaps in Salesforce's trusted URL protections. Without attribution, it could look as if the message was sent by a real employee or IT help desk. In a trusted, internal communications channel, it's likely that nobody would suspect malicious intent.
Related:How AI Agents Can Trigger Runaway Costs for Enterprises
Salesforce Hardens Agentforce Against Phishing
In a statement to Dark Reading, Salesforce acknowledged the vulnerabilities, which do not have CVE numbers, and noted that there has been no evidence that real attackers have exploited them. The company has "updated the default settings for certain Agentforce actions in Slack to require user confirmation before sending messages, and [is] communicating directly with customers to help them review their configurations and make the recommended changes," a spokesperson wrote.
The company also acknowledged that its response to last year's Web-to-lead vulnerability was a quick fix, rather than a comprehensive one. This time around, it has implemented what it believes to be a more robust solution.
Previously, Salesforce's URL redaction control relied on regular expression (regex) matching to identify untrusted URLs in AI agent outputs. Essentially, it checked whether a string of text looked like a URL, allowing clever researchers to conceal their domains in unexpected formats. The company says that it now uses spec-conformant URL parsing, which more meaningfully breaks down and interprets where potential URL strings lead.
Besides the overhauled URL parsing system, Salesforce is also consolidating its URL inspection process. Whereas previously, different parts in an agentic workflow might have each acted upon a URL, now all URL-related AI traffic is funneled through a single gateway that applies more consistent inspection and security rules.
Deeper Issues Plague Agentic Tech
Time will tell whether researchers will break Salesforce's fixes all over again. And as Zenity's analysts point out, there are more structural weaknesses to agentic platforms that URL policies can't account for.
"We've been saying it for years now: The more power you give agents, the more dangerous they are," says Tamir Ishay Sharbat, director of security research at Zenity. "The minute that an agent has the power to send messages by itself to multiple channels, for example, it becomes something that you can abuse. And when you give them access to both sensitive information — your accounts payable, leads, contracts, etc. — and external channels [like Web-to-lead forms], this combination is very toxic."
On top of that toxic combination, agents also have a visibility problem.
"When you buy enterprise software, you assume that it will have logs — that it will have a clear understanding of who did what and why," notes Zenity chief technology officer Michael Bargury. "With agents, because everybody's building fast, the entire market is building black boxes. That makes them more difficult to trust."
"You cannot look at the reasoning, you cannot look at what it does behind the scenes — you only get summaries," Bargury laments. "That's not just a problem in Salesforce; that's pervasive across the industry."
About the Author
Nate Nelson
Contributing Writer
Nate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media.
He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify.
He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself.
Want more Dark Reading stories in your Google search results?
ADD US NOW
More Insights
Industry Reports
The State of Cloud Security: The Latest Challenges
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Essential News & Insights from Black Hat USA 2025
Access More Research
Webinars
Effective Alert Triage: Reducing Noise and Finding Real Threats
Cybersecurity Outlook 2027
Threat Exposure Analytics: Measuring and Communicating Security Risk
Benchmark Scores Are a False Flag
Building an Effective Red Team: Beyond Penetration Testing
More Webinars
You May Also Like
APPLICATION SECURITY
Supply Chain Attack Secretly Installs OpenClaw for Cline Users
by Rob Wright
FEB 19, 2026
APPLICATION SECURITY
Chinese Hackers Hijack Notepad++ Updates for 6 Months
by Jai Vijayan
FEB 02, 2026
APPLICATION SECURITY
Trump Administration Rescinds Biden-Era Software Guidance
by Alexander Culafi
JAN 29, 2026
APPLICATION SECURITY
Microsoft Fixes Exploited Zero Day in Light Patch Tuesday
by Jai Vijayan
DEC 09, 2025
Featured
Check out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show!
Editor's Choice
CYBER RISK
Anthropic CEO: Time to Shift From Improving to Controlling AI
byElizabeth Montalbano
SEP 14, 2026
6 MIN READ
CYBER RISK
Why AI Is So Good at Scamming Humans
SEP 11, 2026
VULNERABILITIES & THREATS
Patch Tuesday Sets Another Record With 974 CVEs
byJai Vijayan
SEP 8, 2026
5 MIN READ
Want more Dark Reading stories in your Google search results?
NOVEMBER 12, 2026 | VIRTUAL
What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI
SAVE YOUR SPOT
Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.
SUBSCRIBE
Discover More
Black Hat
Omdia
Working With Us
About Us
Meet the Editors
Advertise
Reprints
Join Us
NEWSLETTER SIGN-UP
Follow Us
Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466.
Home|
Cookie Policy|
Privacy|
Terms of Use
Your Privacy Choices
首次收录 · 2026-09-25 · 9.92 分