Jessica Entwistle
September 28 2026
Infosecurity Magazine reports that security researchers have identified a set of vulnerabilities, collectively named SalesBleed, affecting Salesforce's Agentforce AI agents. The flaws allow attackers to exploit prompt injection techniques and DNS exfiltration methods to access customer relationship management data without requiring user interaction. The vulnerabilities demonstrate how AI agents, which are designed to autonomously retrieve and process data, can be manipulated to bypass access controls and leak sensitive information through carefully crafted inputs or network-based exfiltration channels. The research highlights a broader challenge facing organisations deploying AI-driven automation: traditional security controls may not adequately protect against attacks that exploit the natural language processing capabilities of AI systems.
Salesforce is widely used across UK businesses for managing customer data, sales pipelines, and service interactions. The introduction of AI agents into these environments creates new attack surfaces that many organisations may not yet have considered. Unlike traditional application vulnerabilities, AI agent flaws can be triggered through natural language inputs, making them harder to detect using conventional security controls. The risk is particularly relevant for organisations deploying AI-driven automation in customer-facing or data-sensitive contexts, where the agent's ability to retrieve and process information could be exploited to access data beyond what the attacker should be able to reach. Prompt injection attacks work by embedding malicious instructions within seemingly legitimate queries, causing the AI agent to perform actions it was not intended to perform. DNS exfiltration allows attackers to extract data through DNS queries, which are often less scrutinised than other network traffic. Together, these techniques represent a new class of risk that organisations must account for when evaluating AI agent deployments.
Organisations using or evaluating Salesforce AI agents should review what data these agents can access, how their permissions are scoped, and whether their activity is being logged and monitored. Ensure that AI agent deployments are treated with the same rigour as any other privileged system integration, including regular access reviews, least privilege principles, and network segmentation where appropriate. Consider implementing input validation and output filtering mechanisms to reduce the risk of prompt injection attacks. Review DNS traffic monitoring capabilities to detect potential exfiltration attempts. Organisations should also ensure that their security teams understand how AI agents operate, what data they can access, and what attack techniques may be used to exploit them. Where AI agents are deployed in production environments, ensure that incident response plans include procedures for investigating and responding to AI-specific security incidents.
Source: Infosecurity Magazine