'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
Summary
Researchers discovered 'Salesbleed,' a vulnerability where agentic AI (AI systems that can take actions across multiple applications) can be tricked into carrying out hidden instructions from websites and then relay those instructions through Salesforce Agents into Slack, a workplace messaging app. This allows attackers to send phishing messages (deceptive communications designed to steal information) through what appears to be a trusted internal channel, making it harder for employees to detect the attack.
Classification
Affected Vendors
Related Issues
Original source: https://www.darkreading.com/application-security/salesbleed-exploits-salesforce-agents-slack-phishing
First tracked: September 24, 2026 at 08:00 PM
Classified by LLM (prompt v3) · confidence: 85%