'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing

2026-09-25T02:51:35Z•10c9c1bccf693a031606879e76a2bc3a3404863baa43f440eb0e41262dcf4426
CVE-2026-76460CVE-2026-85706AI-securityAPTCVECisco-ISEEDR-evasionGitLabM365OAuthOT-securityRATSASEagentic-aiidentity-securitymalwarenation-statephishingprocess-injectionprompt-injectionransomwaresupply-chain-securitythreat-intelligence

What happened

Dark Reading feed covering September 2026 cybersecurity developments, including agentic AI prompt injection and abuse, phishing-as-a-service, malware and RAT campaigns, supply-chain compromises, identity and OAuth threats, nation-state activity, and critical vulnerabilities in Cisco and GitLab products. The most urgent items include CVE-2026-76460, a CVSS 10 Cisco ISE authentication bypass, and CVE-2026-85706, a CVSS 10 GitLab path traversal flaw.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
10c9c1bccf693a031606879e76a2bc3a3404863baa43f440eb0e41262dcf4426
Enrichment time
2026-09-25T02:51:35Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · 'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing · Baitaphish