Prompt injection has been leveraged alongside an expired domain to steal Salesforce data in an attack named ForcedLeak.
Salesforce Agentforce allowed attackers to hide malicious instructions in routine customer forms, tricking the AI into ...