Prompt injection has been leveraged alongside an expired domain to steal Salesforce data in an attack named ForcedLeak.
Salesforce is facing a possible class action lawsuit from almost two dozen plaintiffs who say the SaaS giant should have had better security around its platform, even though a spate of high-profile ...
ForcedLeak flaw in Salesforce Agentforce allows data exfiltration via indirect prompt injection; Salesforce issues patch.
Salesforce Agentforce allowed attackers to hide malicious instructions in routine customer forms, tricking the AI into ...
More fun with AI agents and their security holes A now-fixed flaw in Salesforce’s Agentforce could have allowed external ...
A critical vulnerability chain in Salesforce's AI-powered AgentForce platform has been discovered by cybersecurity ...
Automotive manufacturing giant Stellantis has confirmed that attackers stole some of its North American customers' data after ...
The FBI labeled this group as UNC6395 and apparently, it struck some of the biggest tech and security organizations, ...
The ShinyHunters extortion group claims to have stolen over 1.5 billion Salesforce records from 760 companies using compromised Salesloft Drift OAuth tokens.
Salesforce and CrowdStrike unite to secure the agentic enterprise with AI-driven trust, resilience and real-time threat detection.
TransUnion confirms a major data breach affecting 4.4 million U.S. consumers after hackers exploited third-party Salesforce ...