'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing

An illustration of a dripping cloud
Source: Igor Miller via Getty Images

Vulnerabilities in Salesforce Agentforce, collectively dubbed "Salesbleed" by researchers, could expose customers' internal data and, worse, allow attackers to phish employees from within trusted company channels.

As so often happens with powerful, interconnected AI platforms that excite customers and investors, security and visibility remain hard problems to solve. Researchers at Zenity noted that the three "Salesbleed" weaknesses in Agentforce allow hackers to slowly bleed data from victims via Web-to-lead forms. The most interesting finding, though, is how this seemingly modest Web-to-lead vulnerability can be combined with normal Agentforce workflows to ultimately phish employees from within their most trusted Slack channels.

Building on Issues With Salesforce Web-to-Lead Forms

One year ago, researchers at Noma Security revealed a neat little way to steal corporate data using Salesforce. The trick began with Web-to-lead forms: one of the few contexts on the Internet in which companies will willingly accept near-arbitrary data sent by random individuals. Essentially, sales prospects fill out a registration form to gain access to something, and that lead data is then imported to Salesforce. In the past, attackers might have used Web-to-lead forms to send malicious code. In these agentic days, the researchers figured they could send malicious prompts.

If an attacker presumed that their target was running Agentforce AI agents, it turned out that they could plant a specially crafted AI instruction — for example, an instruction to exfiltrate data to an attacker-controlled URL — in a Web-to-lead form. An agent on the other end of the interaction would ingest and process the instruction, and execute the request inside of the victim company's environment. Salesforce responded to Noma's findings by quickly polishing its rules around URLs that an attacker might use to carry out such an attack. Dark Reading noted at the time that "structural fixes to how its AI processes instructions however remain elusive for now."

This Band-Aid failed to treat the underlying infection, and now, a year later, a new set of researchers from Zenity found that they could perform largely the same attack, using simple workarounds to the URL filtering rules Salesforce implemented in response to last year's findings.

The researchers stressed how convenient their attack was. For one thing, there's no way to identify, suspend, or in any other way punish any passing Internet miscreant using Web-to-lead forms. And by having an AI agent do their bidding for them, attackers can effortlessly piggyback on the typically healthy permissions Salesforce customers willingly grant their bots.

Exploiting Slack via Salesforce Agents

There was just one shortcoming in Zenity's exploit: For any given prompt, an attacker could exfiltrate only as much data as would fit into one subdomain string. That's hardly enough to cause much damage, unless the attacker were looking for very precise data, or automated hundreds or thousands of malicious requests.

But reading and sending data are only two among many powers afforded to Agentforce agents. If agents can do a thousand and one other things for legitimate users, could they do those same things for an attacker?

For example, users can deploy Salesforce agents directly to Slack. Slack agents can be assigned various permissions, in the form of "subagents," which allow them to read or write data. To ensure that they don't perform unwanted actions, agents can be configured to require user confirmation first. They also come with built-in attribution, identifying the human user responsible for a particular agentic action.

However, these controls were missing when it came to an agent's ability to reply to a Slack thread. Zenity researchers reasoned that if an external attacker could inject a malicious prompt into a Web-to-lead form, instead of just exfiltrating data, the instruction could induce a Salesforce bot to reply to an internal company Slack thread, and nothing would stop them from doing it. The message could incorporate social engineering, with a phishing link leveraging those previously described gaps in Salesforce's trusted URL protections. Without attribution, it could look as if the message was sent by a real employee or IT help desk. In a trusted, internal communications channel, it's likely that nobody would suspect malicious intent.

Salesforce Hardens Agentforce Against Phishing

In a statement to Dark Reading, Salesforce acknowledged the vulnerabilities, which do not have CVE numbers, and noted that there has been no evidence that real attackers have exploited them. The company has "updated the default settings for certain Agentforce actions in Slack to require user confirmation before sending messages, and [is] communicating directly with customers to help them review their configurations and make the recommended changes," a spokesperson wrote.

The company also acknowledged that its response to last year's Web-to-lead vulnerability was a quick fix, rather than a comprehensive one. This time around, it has implemented what it believes to be a more robust solution.

Previously, Salesforce's URL redaction control relied on regular expression (regex) matching to identify untrusted URLs in AI agent outputs. Essentially, it checked whether a string of text looked like a URL, allowing clever researchers to conceal their domains in unexpected formats. The company says that it now uses spec-conformant URL parsing, which more meaningfully breaks down and interprets where potential URL strings lead.

Besides the overhauled URL parsing system, Salesforce is also consolidating its URL inspection process. Whereas previously, different parts in an agentic workflow might have each acted upon a URL, now all URL-related AI traffic is funneled through a single gateway that applies more consistent inspection and security rules.

Deeper Issues Plague Agentic Tech

Time will tell whether researchers will break Salesforce's fixes all over again. And as Zenity's analysts point out, there are more structural weaknesses to agentic platforms that URL policies can't account for.

"We've been saying it for years now: The more power you give agents, the more dangerous they are," says Tamir Ishay Sharbat, director of security research at Zenity. "The minute that an agent has the power to send messages by itself to multiple channels, for example, it becomes something that you can abuse. And when you give them access to both sensitive information — your accounts payable, leads, contracts, etc. — and external channels [like Web-to-lead forms], this combination is very toxic."

On top of that toxic combination, agents also have a visibility problem.

"When you buy enterprise software, you assume that it will have logs — that it will have a clear understanding of who did what and why," notes Zenity chief technology officer Michael Bargury. "With agents, because everybody's building fast, the entire market is building black boxes. That makes them more difficult to trust."

"You cannot look at the reasoning, you cannot look at what it does behind the scenes — you only get summaries," Bargury laments. "That's not just a problem in Salesforce; that's pervasive across the industry."

进一步分析

免费工具,针对本文主题进一步深挖分析:

source: DarkReading