Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing

2026-09-24T19:23:51Z•000b035a27993f1e150dc1a6934678e2792f27a1bdd513e7d946302b324ccaf7
AI-securityCISAactive-exploitationagentic-AIcloud-securitycritical-infrastructuredata-breachdata-exfiltrationidentity-and-access-managementmalwaremobile-securityphishingprivacyransomwareremote-code-executionstate-sponsored-cyber-espionagesupply-chain-securityvulnerability-managementzero-day

What happened

A security-news feed covering active exploitation of critical vulnerabilities, data breaches, malware, phishing campaigns, AI-agent and coding-agent security flaws, and state-sponsored cyber operations. The most urgent items include a critical actively exploited F5 BIG-IP APM zero-day RCE, an actively exploited Cisco ISE authentication-bypass flaw, zero-click attacks against Google Pixel devices, and Salesforce Agentforce flaws enabling zero-click CRM data theft and anonymous phishing.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
000b035a27993f1e150dc1a6934678e2792f27a1bdd513e7d946302b324ccaf7
Enrichment time
2026-09-24T19:23:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing · Baitaphish