Новости компьютерной безопасности:

  Latest News

Salesforce AI Agent Vulnerability Allows Let Attackers Exfiltration Sensitive Data

С сайта: Vulnerability(cybersecuritynews.com)

Salesforce AI Agent Vulnerability Allows Let Attackers Exfiltration Sensitive Data

Author: Guru Baran

A critical vulnerability chain in Salesforce’s Agentforce AI platform, which could have allowed external attackers to steal sensitive CRM data.

The vulnerability, dubbedForcedLeakby Noma Labs, which discovered it, carries a CVSS score of 9.4 and was executed through a sophisticated indirect prompt injection attack.

This discovery highlights the expanded and fundamentally different attack surface presented by autonomous AI agents compared to traditional systems.

Upon notification from Noma Labs, Salesforce promptly investigated the issue and has since deployed patches. The fix prevents Agentforce agents from sending data to untrusted URLs, addressing the immediate risk.

The research demonstrates how AI agents can be compromised through malicious instructions hidden within what are normally considered trusted data sources.

cyber security news
ForcedLeak Attack
The attack exploited several weaknesses, including insufficient context validation, overly permissive AI model behavior, and a critical Content Security Policy (CSP) bypass.

Attackers could create a malicious Web-to-Lead submission containing unauthorized commands. When the AI agent processed this lead, the Large Language Model (LLM) treated the malicious instructions as legitimate, leading to the exfiltration of sensitive data.

The LLM was unable to differentiate between trusted data loaded into its context and the attacker’s embedded instructions.

The attack vector was an indirect prompt injection. Unlike a direct injection, where an attacker inputs commands straight into the AI, this method involves embedding malicious instructions in data that the AI will later process during a routine task.

In this case, the attacker placed a payload in the “Description” field of a web form, which was then stored in the CRM. When an employee asked the AI agent to review the lead, the agent executed the hidden commands.

A key factor in the success of this attack was the discovery of a flaw in Salesforce’s Content Security Policy. The researchers found that the domain my-salesforce-cms.com was whitelisted but had expired and was available for purchase.


Salesforce has since re-secured the expired domain and implemented stricter security controls, including Trusted URLs Enforcement for both Agentforce and Einstein AI, to prevent similar issues.

If exploited, ForcedLeak could have had severe consequences. The vulnerability risked exposing confidential customer contact information, sales pipeline data, internal communications, and historical interaction records.

Any organization using Salesforce Agentforce with the Web-to-Lead feature enabled was potentially vulnerable, especially those in sales and marketing who regularly process external lead data.

Salesforce recommends that customers take the following actions:

  • Apply the recommended updates to enforce Trusted URLs for Agentforce and Einstein AI.
  • Audit existing lead data for any suspicious submissions containing unusual instructions.
  • Implement strict input validation and sanitize all data from untrusted sources.




    #Cyber_Security_News #Vulnerability #Vulnerability_News #cyber_security #cyber_security_news #vulnerability

    Оригинальная версия на сайте: Salesforce AI Agent Vulnerability Allows Let Attackers Exfiltration Sensitive Data
    Вернуться к списку новостей К свежим новостям Здесь был google AdSense.
    Вместо рекламы товаров началась политическая агитация.
    Отключено до получения извинений.

    Вернуться к списку новостей Здесь был google AdSense.
    Вместо рекламы товаров началась политическая агитация.
    Отключено до получения извинений.


    Новости проекта CSN:

    ✉ CSN.net4me.net

    Обновление сайта csn.net4me.net

    Обновление сайта csn.net4me.net 💻
    cyber security news
    • Физически мы переехали на новый сервер. Благодарим наших подписчиков и постоянных читателей за терпение и понимание.
    • Сайт csn.net4me.net полностью адаптирован для работы по шифрованному SSL соединению.
    • Изменен механизм обработки и отображения опасных и критических уязвимостей.

    Благодарим что вы с нами.


    #CSN_обновление_сайта
    https://csn.net4me.net/cyber_security_8301.html

    Дополнительный материал

    О проекте CSN

    Проект CSN.net4me.net родился 16 Марта 2018 года.
    Проект находится в самом начале своего развития. Конечно оформление, наполнение будет меняться. Одно останется неизменным - самые свежие новости компьютерной и сетевой безопасности.

    О проекте net4me

    Проект net4me.net развивался как сборник готовых решений и документации по темам компьютерной безопасности, сетевых решений и СПО (в часности linux). Темпы развития IT отрасли оказались столь быстрыми, что некоторые знания, технологии и информация о них устаревали мгновенно. Тем не менее, некоторый материал net4me.net до сих пор востребован.

    Об источниках

    Новости берутся CSN из открытых и доступных каждому источников. Авторы проекта стараются подбирать авторитетные и проверенные источники. Но, тем не менее, не несут ответственности за содержимое новостей. В каждой новости указывается источник этой новости, её автор и ссылка на оригинал новости.

    Информация

    Если вы желаете чтобы новости вашего ресурса были размещены на сайте CSN, то свяжитесь с авторами проекта csn@net4me.net и предложите ссылку на rss или xml ленту новостей вашего ресурса. Любая предложенная информация будет рассмотрена редакцией.