logo

Smashing Security podcast #437: Salesforce’s trusted domain of doom

ID: 4d241437-2cea-57bf-b49d-a5c3c0847a13

STIX ID: report--4d241437-2cea-57bf-b49d-a5c3c0847a13

Feed Name: Graham Cluley

Threat Score
30/100

Date Published: 2025-10-01

Date Updated: 2026-04-22

Author: Graham Cluley

...
...

The Smashing Security podcast episode describes researchers discovering a vulnerability in Salesforce Agentforce called “ForcedLeak” that allowed attackers to inject AI-readable instructions through a Web-to-Lead form and exfiltrate data for a reported cost of five dollars; the episode covers the flaw and broader discussion about breach communications rather than providing a detailed technical analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.