Would Ethosure have caught this? — Salesforce Agentforce’s ForcedLeak indirect prompt injection

Noma Labs’ Sasi Levi demonstrated a CVSS 9.4 chain in Salesforce Agentforce: a malicious Web-to-Lead submission stored 42,000 characters of injected instructions in the CRM, then exfiltrated data through a rendered image on an expired trusted domain. Salesforce patched via Trusted URLs Enforcement on September 8, 2025. Tenant-owned CRM records were the prompt-injection vector. The fix is policy on the agent, not just on the domain allowlist.

Would Ethosure have caught this? — the Nx s1ngularity attack that weaponised developers’ own AI CLIs

Attackers pushed eight trojanised Nx releases to npm on August 26, 2025. The postinstall script invoked victims’ own Claude Code, Gemini CLI, and Amazon Q binaries with safety flags disabled and told them to hunt for secrets. Roughly 1,000 valid GitHub tokens, dozens of cloud credentials, and 5,500 private repositories were exposed. First documented case of a supply-chain payload deliberately using the developer’s AI assistant as an amplifier.

Subscribe to Ethosure's Newsletter to get monthly updates on AI Governance

We don’t spam! Read our privacy policy for more info.