A new attack vector called "Salesbleed" exploits Salesforce Agents to inject phishing content directly into Slack, bypassing traditional security controls by weaponizing AI automation workflows.

Security researchers discovered the vulnerability chains together Salesforce Agent functionality with Slack integration to create a delivery mechanism for credential theft and social engineering attacks. The attack works by embedding malicious instructions within web content that Salesforce Agents consume and execute. When the agent processes these instructions, it automatically forwards crafted messages to Slack channels, making the phishing appear as though it originates from trusted internal systems rather than external threat actors.

The core problem centers on how modern agentic AI systems interpret and execute instructions. Salesforce Agents function as automation tools that can interact with multiple applications and data sources. When these agents fetch content from the web as part of their normal operations, they may encounter hidden instructions designed to redirect their behavior. An attacker can embed these instructions in seemingly benign web pages, emails, or documents that the agent accesses during its workflow. The agent then executes those redirected instructions without human oversight, creating a privilege escalation where the agent's trusted status bypasses security filters.

Slack integration amplifies the threat considerably. Slack channels within organizations serve as primary communication hubs for sensitive discussions, file sharing, and decision-making. Messages appearing to come from internal automation systems carry inherent credibility. Phishing messages delivered through this channel face lower scrutiny than external emails because employees see them arriving through what appears to be legitimate internal systems. An attacker can craft messages requesting password resets, two-factor authentication codes, or sensitive documents. The internal origin makes victims significantly more likely to comply without verification.

The vulnerability affects any organization deploying Salesforce Agents with Slack connectivity. The risk scales with agent complexity and the number of external data sources the agent accesses during operation. Organizations relying heavily on agent automation for customer service, lead management, or internal workflows face heightened exposure. Attackers can target victims with extreme precision by sending personalized phishing through Slack, leveraging employee directory information or customer data already stored in Salesforce systems.

Detection and prevention require multi-layered approaches. Organizations should restrict Salesforce Agent permissions to only essential functions and limit external data source access. Slack webhook restrictions and message filtering rules can catch anomalous agent behavior. Human review processes for sensitive agent-generated communications add friction that disrupts automated attack chains. API token rotation and zero-trust authentication between Salesforce and Slack prevent token reuse if compromise occurs.

The Salesbleed discovery reflects a broader vulnerability class in agentic AI systems. As organizations deploy agents with increasing autonomy and cross-application access, the attack surface expands. Agents can become unwitting accomplices in sophisticated attacks if malicious instructions reach them through any connected channel. Security teams must view agent integration as equivalent to granting new user accounts with elevated privileges. The automation benefit comes with the responsibility of treating agent security with the same rigor as human account management.