Tag: CRM Data

Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection
News

Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection

Researchers studying cybersecurity have found a serious vulnerability in Salesforce Agentforce, a platform for creating artificial intelligence (AI) agents, that may enable hackers to use an indirect prompt injection to steal confidential information from the CRM tool. On July 28, 2025, Noma Security identified and reported the vulnerability, which they have nicknamed ForcedLeak (CVSS score: 9.4). It affects any company that uses Salesforce Agentforce and has Web-to-Lead enabled. This flaw illustrates how, in contrast to conventional prompt-response systems, AI agents offer a radically different and wider attack surface. According to a source provided to The Hacker News, Sasi Levi is the lead for security research at Noma. Indirect prompt injection, which happens when malicious i...