Malicious AI agent skill bypasses Salesforce AppExchange security checks, reaches 26,000 users via Instagram

According to security research firm AIR, a fake AI agent skill labeled "brand-landingpage" passed Salesforce's static security scanning and was distributed to over 26,000 users through Instagram, some tied to corporate accounts. AIR said the skill redirected to a controlled domain and later altered its payload to collect user email addresses. The incident demonstrates that static scanning failed to detect the attack, raising risks as enterprises deploy AI agents across systems.

Topics

AI securitySalesforce

Sources

Go deeper

This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.