September 28, 2026

AI Agent Security Risks: What Southwest Florida Businesses Need to Know

A newly disclosed flaw in Salesforce’s Agentforce AI let an outside attacker pull customer data out of a company’s CRM without logging in or getting anyone to click a link, simply by hiding instructions inside a public contact form. It is a clear example of the AI agent security risks that come with connecting any AI assistant to real business data, and the weakness is not unique to Salesforce. If your business runs AI agents inside Microsoft 365, a help desk tool, or a CRM, the same category of flaw can exist in your setup too.

  • Researchers at Zenity Labs found three flaws in Salesforce’s Agentforce AI, nicknamed SalesBleed, that allowed CRM data theft with no login and no click from the victim.
  • The entry point was a public web form. An attacker hid instructions inside a routine lead submission, and the AI agent later read and obeyed them as if they came from a trusted employee.
  • This attack method, indirect prompt injection, works against any AI agent that reads outside content: emails, web forms, shared documents, support tickets.
  • Microsoft 365 Copilot agents, chatbots, and other connected AI tools carry the same category of risk if their access is not scoped and reviewed.
  • Salesforce shipped fixes for all three flaws by August 19, 2026, but the lesson for small businesses is to audit what data any AI agent can reach before relying on it.

What did the Salesforce AI agent flaw actually do?

According to Zenity Labs’ technical writeup, an attacker could submit a normal-looking lead through a company’s public Web-to-Lead form with hidden instructions buried in a form field. When a sales rep later asked their Agentforce AI agent to summarize or process that lead, the agent treated the hidden text as a legitimate command. Two of the three flaws let data leave the company silently through a DNS query, with no employee action required. A third let an attacker impersonate a trusted, Agentforce-connected Slack bot to send convincing internal phishing messages. As The Register reported, Salesforce fixed the issues after Zenity disclosed them in June 2026 and found no evidence the flaws were exploited before the patch.

Why should a Southwest Florida small business care about a Salesforce bug?

Most small businesses in Naples, Fort Myers, and Tampa are not running Salesforce Agentforce. That is beside the point. The pattern matters more than the product. Any AI agent connected to a real data source, whether that is a CRM, a mailbox, a ticketing system, or a Microsoft 365 Copilot agent, can potentially be steered by content it was never supposed to trust. A growing number of SMBs have turned on some form of AI agent this year without a clear picture of what that agent can see or do. If nobody at your company can answer the question of what data your AI assistant can reach right now, that gap is the actual risk, not the Salesforce headline.

What is indirect prompt injection, in plain terms?

Think of an AI agent as a new employee who reads everything handed to them and follows instructions without questioning where they came from. Indirect prompt injection means an attacker writes those instructions somewhere the AI will eventually read, a support ticket, a web form, an email, or a shared file, instead of typing them directly into a chat window. The AI has no reliable way to tell a legitimate internal request from a hidden command planted by a stranger. We covered a related Microsoft defense for this exact problem in our post on Microsoft’s new prompt injection protection and why it skips most Business Premium inboxes, which is worth a read if your team uses Copilot.

What should you check before trusting an AI agent with your data?

Start with an inventory. List every AI agent, chatbot, or Copilot feature connected to a business system, and note what data each one can read and what actions it can take on its own. Turn off any permission the agent does not need for its actual job. Where the tool allows it, require a human approval step before an AI agent sends data outside your systems or takes an irreversible action. Review those permissions on a set schedule instead of assuming a one-time setup is enough, since vendors add new AI features and connections constantly. If your team has not done this review yet, it belongs on the same list as your other quarterly security checks, alongside the broader gaps we outlined in closing the AI cybersecurity gap for Southwest Florida small businesses.

Frequently asked questions

Does this Salesforce flaw affect my business if I don’t use Salesforce?
Not that specific bug, but the technique behind it, hiding instructions inside content an AI agent later reads, works against any AI agent that processes outside input, including Microsoft 365 Copilot agents, chatbots, and help desk tools.

What is indirect prompt injection?
It is when an attacker hides instructions inside content an AI agent will read later, such as a web form, email, or document, so the AI carries out those instructions as if a trusted user gave them.

How do I know what data an AI agent in my business can access?
Check the agent’s connected data sources and permissions in the admin settings of the tool it runs in. If you cannot find that screen or nobody has reviewed it, treat that as your starting point.

Is turning off AI agents the safest option?
Not necessarily. AI agents are useful when scoped correctly. The safer path is limiting what each agent can read and do, reviewing its permissions periodically, and keeping a human in the loop for anything involving sensitive data.

SWFIT can run a free 15-minute review of the AI tools and agents connected to your Microsoft 365 environment and tell you plainly what they can access. Contact us to schedule your review before your next AI feature rollout, not after.

About the Author

Leave a Reply

Your email address will not be published. Required fields are marked *

Your IT Partner Is Just a Click Away

Contact us now to explore customized IT solutions that drive efficiency, security, and success for your business.