Information security
fromTheregister
2 weeks agoSalesforce Agentforce tricked into leaking sales leads
A DNS misconfiguration in Salesforce Agentforce enabled prompt-injection exfiltration of CRM data via an expired trusted domain; Salesforce patched and enforced trusted URL allow-lists.