'Salesbleed' Flaw Shows How AI Agents Can Be Tricked Into Launching Phishing Attacks
A newly identified attack technique, dubbed 'Salesbleed,' demonstrates how agentic AI tools connected to Salesforce can be exploited to spread phishing content through Slack. According to researchers, the AI agents can be tricked into pulling in hidden instructions from web content they process, then passing those instructions along into internal communication channels that employees normally trust.
This matters because agentic AI systems are increasingly linked across multiple business applications, such as CRM platforms and team chat tools, to automate tasks. If an attacker can plant malicious instructions somewhere the AI agent reads from, such as a webpage or document, that content can move undetected into internal channels like Slack, where staff are less likely to suspect phishing attempts. This bypasses traditional email based phishing defences entirely.
While full technical details are limited in this report, the core risk is clear: AI agents that connect multiple apps together can become a pathway for attackers to reach employees through unexpected, trusted channels.