Close Menu
  • Home
  • AI Models
    • DeepSeek
    • xAI
    • OpenAI
    • Meta AI Llama
    • Google DeepMind
    • Amazon AWS AI
    • Microsoft AI
    • Anthropic (Claude)
    • NVIDIA AI
    • IBM WatsonX Granite 3.1
    • Adobe Sensi
    • Hugging Face
    • Alibaba Cloud (Qwen)
    • Baidu (ERNIE)
    • C3 AI
    • DataRobot
    • Mistral AI
    • Moonshot AI (Kimi)
    • Google Gemma
    • xAI
    • Stability AI
    • H20.ai
  • AI Research
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Microsoft Research
    • Meta AI Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding & Startups
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • Expert Insights & Videos
    • Google DeepMind
    • Lex Fridman
    • Matt Wolfe AI
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • Matt Wolfe AI
    • The TechLead
    • Andrew Ng
    • OpenAI
  • Expert Blogs
    • François Chollet
    • Gary Marcus
    • IBM
    • Jack Clark
    • Jeremy Howard
    • Melanie Mitchell
    • Andrew Ng
    • Andrej Karpathy
    • Sebastian Ruder
    • Rachel Thomas
    • IBM
  • AI Policy & Ethics
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
    • EFF AI
    • European Commission AI
    • Partnership on AI
    • Stanford HAI Policy
    • Mozilla Foundation AI
    • Future of Life Institute
    • Center for AI Safety
    • World Economic Forum AI
  • AI Tools & Product Releases
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
    • Image Generation
    • Video Generation
    • Writing Tools
    • AI for Recruitment
    • Voice/Audio Generation
  • Industry Applications
    • Finance AI
    • Healthcare AI
    • Legal AI
    • Manufacturing AI
    • Media & Entertainment
    • Transportation AI
    • Education AI
    • Retail AI
    • Agriculture AI
    • Energy AI
  • AI Art & Entertainment
    • AI Art News Blog
    • Artvy Blog » AI Art Blog
    • Weird Wonderful AI Art Blog
    • The Chainsaw » AI Art
    • Artvy Blog » AI Art Blog
What's Hot

C3.ai: Stay Patient Through The Transition (NYSE:AI)

Automated Structured Radiology Report Generation with Rich Clinical Context – Takara TLDR

The ghost in the machine

Facebook X (Twitter) Instagram
Advanced AI News
  • Home
  • AI Models
    • OpenAI (GPT-4 / GPT-4o)
    • Anthropic (Claude 3)
    • Google DeepMind (Gemini)
    • Meta (LLaMA)
    • Cohere (Command R)
    • Amazon (Titan)
    • IBM (Watsonx)
    • Inflection AI (Pi)
  • AI Research
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Meta AI Research
    • Microsoft Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • AI Experts
    • Google DeepMind
    • Lex Fridman
    • Meta AI Llama
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • The TechLead
    • Matt Wolfe AI
    • Andrew Ng
    • OpenAI
    • Expert Blogs
      • François Chollet
      • Gary Marcus
      • IBM
      • Jack Clark
      • Jeremy Howard
      • Melanie Mitchell
      • Andrew Ng
      • Andrej Karpathy
      • Sebastian Ruder
      • Rachel Thomas
      • IBM
  • AI Tools
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
  • AI Policy
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
  • Business AI
    • Advanced AI News Features
    • Finance AI
    • Healthcare AI
    • Education AI
    • Energy AI
    • Legal AI
LinkedIn Instagram YouTube Threads X (Twitter)
Advanced AI News
Customer Service AI

A Customer Service AI Agent Spits Out Complete Salesforce Records in an Attack by Security Researchers

By Advanced AI EditorAugust 18, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


Microsoft has published many examples of how businesses can build AI agents in Copilot Studio to automate multi-step tasks, without a human in the loop.

One such example, as shared on YouTube, is a customer service agent built by McKinsey & Co..

The AI agent autonomously interacts with customers, scouring internal knowledge bases and data systems to share responses to their queries.

Such a possibility represents a major leap for customer-facing chatbots, which, until recently, relied on rigid decision trees that broke whenever customers went off-script.

Thanks to this tech advancement, Gartner has predicted that agentic AI will solve 80 percent of customer problems by 2029.

Microsoft Copilot Studio has quickly become a hallmark platform for building AI agents that converse with customers.

Yet, researchers from Zenity, the security and governance platform provider, wanted to test how safe the customer-facing agents built on Copilot Studio are.

As such, the firm created a replica of McKinsey’s model, hooked it to a Salesforce sandbox org, and started “attacking it like it’s the last agent on earth.”

The result, shared at DEF CON 2025, proved nothing short of remarkable. Indeed, the researchers made the agent act without human verification, reveal private knowledge and internal tools,  and share complete Salesforce CRM records.

Since then, the Zenity team has released a video of their attack, showcasing how it breached the AI agent, after Microsoft confirmed the injection no longer works.

However, while this attack may fail on Copilot Studio agents today, Zenity warns that over 3,500 public-facing agents remain wide open to similar prompt injections.

As such, more examples of “agent aijacking” are just waiting to happen, and it may not be the good guys doing it next around.

Summing up, Michael Bargury, Co-Founder & CTO of Zenity, stated:

Agent aijacking is not a vulnerability you can fix. It’s inherent to agentic AI systems, a problem we’re going to have to manage.

If businesses can’t manage this vulnerability while granting AI agents access to internal systems, they risk large-scale data breaches.

Indeed, the demo highlights how AI agents, without an overarching governance structure, can turn into data extraction tools, attacking CRMs, internal communications, and billing information.

Taking note of this, David Villalon, Co-founder & CEO of Maisa, warned on LinkedIn:

For enterprises rushing to deploy autonomous AI: this is your warning. Every autonomous agent with data access is a potential attack vector. The convenience of “no human in the loop” becomes a catastrophic vulnerability when security fails.

“The gap between AI capability and AI security keeps widening,” continued Maisa. “We’re building powerful autonomous systems on foundations that hackers can compromise with clever prompts.”

Given this, Maisa suggested that it might be time for brands to reconsider what “autonomous” means in enterprise AI, especially regarding customer-facing use cases.

More Attacks on Salesforce Data

While the ethical attack on the Copilot-built AI agent may not have spewed out any real Salesforce records, other recent not-so-ethical attacks have.

Crucially, these are not the fault of Salesforce’s security posture. Instead, they target the people using Salesforce’s software through more conventional human-centric means.

The latest attack targeted Workday. As shared in a company blog post last week, bad actors contacted employees “pretending to be from human resources or IT.”

In doing so, they stole “some information from our third-party CRM platform”, which Bleeping Computer has since asserted was Salesforce.

The week prior, another Salesforce instance was breached, this time at Google.

Yet, the attack method was different. In this case, the fraudsters tricked admins into installing a malicious version of Salesforce Data Loader.

The fake solution mimicked Data Loader, extracting, updating, and deleting Salesforce data. But it also allowed attackers to quietly lift sensitive data from the backend.

Both attacks, which notably breached two enterprise tech giants, are a reminder that any organization can fall victim to such attacks.

Indeed, this isn’t a dig at Salesforce. Every customer database is vulnerable, and – unfortunately – the tools available to attackers are multiplying.

Whether through AI-generated deepfakes or manipulating new attack surfaces, the pressure on cybersecurity teams is reaching new heights.

 

 



Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleTensorZero nabs $7.3M seed to solve the messy world of enterprise LLM development
Next Article MacDowell’s Chiwoniso Kaitano Wants to Center Artist Residencies
Advanced AI Editor
  • Website

Related Posts

When AI Companions Become Your Marketers: The Digital Love Affair That Went Too Far

October 5, 2025

Cisco Unveils AI-Powered Tools to Transform Contact Center Experience

October 5, 2025

Delivering telecommunications of the future with agentic AI

October 3, 2025

Comments are closed.

Latest Posts

Former ARTnews Publisher Dies at 97

National Gallery of Art Closes as a Result of Government Shutdown

Almine Rech Closes London Gallery After More Than a Decade

Record Exec and Art Collector Gets Over 4 Years

Latest Posts

C3.ai: Stay Patient Through The Transition (NYSE:AI)

October 6, 2025

Automated Structured Radiology Report Generation with Rich Clinical Context – Takara TLDR

October 6, 2025

The ghost in the machine

October 6, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • C3.ai: Stay Patient Through The Transition (NYSE:AI)
  • Automated Structured Radiology Report Generation with Rich Clinical Context – Takara TLDR
  • The ghost in the machine
  • LongCodeZip: Compress Long Context for Code Language Models – Takara TLDR
  • VIRTUE: Visual-Interactive Text-Image Universal Embedder – Takara TLDR

Recent Comments

  1. Edwardloogy on 1-800-CHAT-GPT—12 Days of OpenAI: Day 10
  2. BrandonUttep on Trump’s Tech Sanctions To Empower China, Betray America
  3. BrandonUttep on Sam & Jony introduce io
  4. BrandonUttep on Implement human-in-the-loop confirmation with Amazon Bedrock Agents
  5. BrandonUttep on This AI Hallucinates Images For You

Welcome to Advanced AI News—your ultimate destination for the latest advancements, insights, and breakthroughs in artificial intelligence.

At Advanced AI News, we are passionate about keeping you informed on the cutting edge of AI technology, from groundbreaking research to emerging startups, expert insights, and real-world applications. Our mission is to deliver high-quality, up-to-date, and insightful content that empowers AI enthusiasts, professionals, and businesses to stay ahead in this fast-evolving field.

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

LinkedIn Instagram YouTube Threads X (Twitter)
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
© 2025 advancedainews. Designed by advancedainews.

Type above and press Enter to search. Press Esc to cancel.