Salesforce Agentforce AI Agent Vulnerability

Salesforce Agentforce AI agent vulnerability let a web form hijack CRM data with zero clicks. Patched already, but the pattern will repeat elsewhere.

A Salesforce Agentforce AI agent vulnerability, publicly disclosed September 24 by research firm Zenity Labs under the name “SalesBleed,” let an attacker plant a hidden instruction in an ordinary sales lead form and later exfiltrate CRM data with zero clicks, once an employee simply asked their AI agent to look at the newest lead. Salesforce…

Read More

Top 5 Cybersecurity News Stories August 7, 2026

This week’s Top 5 Cybersecurity News Stories August 7, 2026 follows a single structural pattern expressed differently across all five incidents: the attack reached its target not by defeating a security control but by exploiting a trust assumption the security model had treated as a given. An AI agent trusted to operate within the boundaries…

Read More

Langflow CVE-2026-55255 KEV: AI Agent Flaw Explained

Langflow CVE-2026-55255 KEV

The Langflow CVE-2026-55255 KEV entry, added by CISA on July 7, marks the first time an AI agent orchestration platform has ever appeared in the Known Exploited Vulnerabilities catalog. The flaw carries a CVSS score of just 6.1 from CISA, yet KEVIntel and CIRCL independently score the same bug 9.9, because it lets an authenticated…

Read More