Salesforce Vulnerabilities Expose CRM Data to Zero-Click Attacks Security researchers disclosed three vulnerabilities in Salesforce Agentforce, collectively named SalesBleed, that allowed attackers to hijack AI agents, steal sensitive CRM data, and send phishing messages with zero clicks from a victim. One expert framed the flaws as a lesson in what it takes to keep AI agents contained. Meet SalesBleed, a trio of security flaws in Salesforce Agentforce that allowed hackers to hijack AI agents, steal sensitive CRM data, and send phishing messages - all without a single click. These vulnerabilities exposed the power of unchecked AI, as one expert warned: it's a lesson in what it takes to keep AI agents contained.