Another zero-day patched just in time for no one to notice. This Friday, September 25, 2026 security news buffet includes the usual mix: cloud-ish techno-babble, Internet-facing software that forgot security is a feature, and vendors telling you everything is fine while your risk score slowly catches fire in the background. Pour yourself something, preferably scotch or bourbon. You are going to need the emotional support.
The One Story That Matters (Because It Roasts the Modern Stack)
The headline act is “SalesBleed” Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration. Translation: trusted automation, hijacked, turned into an extraction engine, and then pointed at humans to finish the job with phishing. “Zero-click” is the security industry’s favorite magic trick. It’s not magic. It’s just bad assumptions about how “trusted” systems behave when attackers get a foothold.
Salesforce Agentforce is supposed to be the kind of thing CISOs love to put on slides. “AI-enabled agent workflows.” “Efficiency.” “Trusted environment.” Sure. Until the attacker finds a crack in the trust boundary and uses your own privileged expectations as a crowbar.
Why This Is a Vendor Love-Story You Should Not Trust
Let’s be blunt: when your security model depends on “the agent is trusted,” you don’t have security. You have hope with compliance paperwork stapled to it. The “SalesBleed” type of issue is especially nasty because it turns the automation layer into a weapon. And once a system can reliably access data and execute actions, it stops being a “reporting tool” and becomes a data exfiltration pipeline with opinions.
This is also the classic IT culture problem. Teams love “managed” anything because it reduces local responsibility. Then the day comes when the managed system becomes the incident, and suddenly everyone is asking what happened, who approved it, and whether the vendor has a timeline. Vendors, of course, have timelines. They just do not align with your business needs or your executive’s patience.
What You Should Do Instead of Posting a Ticket
If you’re using agentic workflows (whether Salesforce agents, internal automations, or whatever the flavor of the week is), your security homework is not optional. You need controls that assume compromise:
1) Tighten what agents can access. Least privilege is not a poster. It’s a survival tactic.
2) Add egress and data access monitoring that detects unusual agent behavior, not just user logins.
3) Treat automation as an identity with its own risk model. If an agent can exfiltrate data, then it needs compensating controls like any other high-privilege account.
Bottom Line
This story is a reminder that “trusted systems” are only as trustworthy as the boundaries that separate them from attackers. And in 2026, those boundaries keep getting negotiated like they’re optional clauses in a service agreement.
Read the original: SalesWeek – SalesBleed Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration