Salesforce agents could turn trusted Slack threads into phishing
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Friday, September 25th, 2026.
External input could have induced Salesforce Agentforce bots to post phishing messages inside trusted company Slack threads. Researchers placed malicious instructions in public Web-to-lead forms, which an agent could later process inside a customer environment. The technique could also extract limited amounts of data. But the Slack path was more concerning because a message could appear in an internal thread without the expected confirmation or clear attribution to a human user.
Salesforce said it found no evidence of malicious exploitation. The company changed default Slack settings to require confirmation for certain actions, replaced weaker URL matching with standards-based parsing, and centralized URL inspection. Even so, the broader architecture deserves attention. An agent that connects public input, internal information and trusted messaging channels can become a powerful bridge for abuse. Defenders should review Agentforce permissions, confirmation settings, connected channels and audit visibility. Filtering one prompt or URL pattern won’t replace firm limits on what an agent can do. Require human approval for agent messages and minimize access between public inputs, sensitive data and internal communications.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.