Visualização de leitura

Salesforce offers more Agentforce credits to drive adoption

Salesforce is updating some of the editions, or pricing tiers, of Agentforce Sales and Agentforce Service, a year after their rebrand from Sales Cloud and Service Cloud. The top three now bundle AI agents, analytics, Slack, security, and support with larger allocations of Flex Credits; two of the tiers are also increasing in price.

The Core edition replaces the old Enterprise edition, and its price goes up from $175 per user per month to $195, and now includes 500,000 Flex Credits. Advanced edition costs $395 per user per month and includes 1 million credits, replacing the $350 per month Unlimited edition. The Max edition replaces the old Agentforce 1 tier and now includes 2.75 million credits instead of 1 million for the same $550 per month fee, Salesforce said in a blog post.

The lowest tiers, Starter and Pro Suite, remain unchanged in features and price, although there is a hint that Salesforce is renaming the latter to Professional edition.

What is new in Agentforce Sales?

The new editions bring several capabilities to the base subscription of Agentforce Sales that were previously sold separately: The Core edition now includes Momentum, Slack Business+, and Tableau Next, while the Advanced edition adds Sales Programs, the Premier Success Plan, and additional security and data-protection capabilities. Max edition adds Agentforce for Sales, Agentforce Coworker, Salesforce Spiff, Sales Planning, Sales Programs, Salesforce Maps, Slack Enterprise+, and additional Tableau Next capabilities.

Under the previous Enterprise and Unlimited editions, Sales Programs was an add-on, Tableau Next was available through a separate Tableau+ purchase, and Agentforce itself had to be purchased separately.

What is new in Agentforce Service?

The new editions of Agentforce Service also incorporate capabilities that previously required additional purchases.

The Core edition includes case management, self-service Help Center, Slack Business+, and Slackbot; Advanced adds Agentforce Help Agent, Premier Success Plan, full sandbox, Backup & Recover, and Data Detect, and Max adds Service Rep Assistant, Workforce Engagement, Quality Management, IT Service, unmetered Agentforce Coworker access, and a library of service agent templates.

Under the previous Enterprise and Unlimited editions, Agentforce was available as a separate purchase, while capabilities such as additional security, data protection, and workforce-management tools were also packaged separately or reserved for higher-tier offerings.

Procurement simplicity could come at the cost of visibility

Salesforce said the new editions deliver from 50% to 70% greater value than those they replace, but realizing that value may not be straightforward, analysts warned, particularly as enterprises move from experimenting with Agentforce to deploying agents at scale.

While bundling more AI, analytics, security, Slack, and support capabilities into the subscriptions could simplify procurement of Salesforce products for enterprises, the economics could become more complicated once customers start consuming their included Flex Credits, said Manoj Chandra Jha, principal analyst at Nord-IQ Research.

That is because bundling more capabilities into a single subscription reduces the line-item visibility CIOs previously relied on, and most enterprise finance teams are still learning how to forecast for credit consumption, he said.

Without that visibility CIOs will find it hard to assess how Salesforce’s offerings compare with competing products, particularly when they are trying to determine the cost of specific capabilities or decide which components of a broader bundle are delivering value, he said.

Salesforce may be exaggerating the real value of the new editions, said Pareekh Jain, principal analyst at Pareekh Consulting.

“While CIOs may get more capabilities in a single package, they will still need to assess how much of that functionality employees actually use. A package may offer 60% more theoretical value, but that benefit can disappear if much of the bundled functionality or Flex Credits goes unused,” he said.

Overuse is also a problem, said Jha: As agent usage grows, enterprises could consume their included Flex Credits more quickly and eventually need to purchase additional credits, making actual usage a more important measure of value that CIOs should follow rather than the headline savings attached to the new editions, Jha noted.

New editions targeted at accelerating adoption

While Salesforce talks of value for money, analysts see its real goal with the new editions as accelerating Agentforce adoption.

Investment analysts raised concerns about questioned Agentforce’s customer traction in July, citing enterprise data readiness and the product’s maturity as factors holding back broader adoption. Salesforce, however, has pushed back, pointing instead to growth in deployments and usage.

Nevertheless, said Jha, “With Agentforce running at only a fraction of Salesforce’s 150,000-plus customer base, and analysts pinning the drag on messy enterprise data, folding security and analytics into every tier looks like Salesforce neutralizing the objection before a prospect can raise it.”

Salesforce said last month that its customers had increased their average number of agents from five in February 2025 to 13 by April 2026, while the average number of agent actions per account grew at a 31% compound monthly growth rate over the same period.

Jha sees the updated editions as aimed primarily at Salesforce’s existing customer base, giving companies already using its products more incentives and capacity to expand their use of Agentforce, rather than as a draw for new customers.

Salesforce said the new editions for Agentforce Sales and Agentforce Service are already available, and will soon be joined by new editions for Agentforce Industry.

Existing Agentforce 1 edition customers can upgrade to the new Max edition at no additional cost, the company said, adding that in the future, Max editions across its Sales and Service offerings will also include an allocation for Headless 360.

Salesforce, Anthropic partner to deliver Claudeforce

Salesforce and Anthropic today announced they have expanded their strategic partnership to deliver Claudeforce, enabling customers of both companies to leverage Salesforce data, workflows, business logic, actions, and governance within Claude.

“What we’re seeing is that when people stop using Salesforce through the traditional human interface and start using it through an agentic interface, it dramatically increases the value of Salesforce,” Patrick Stokes, president of Applications & Marketing at Salesforce, told CIO.com on Wednesday. “They’re using Salesforce more than they ever have before.”

Stokes explained that momentum around the Claudeforce partnership began building after Salesforce’s TDX 2026 developer conference earlier this year. At the conference, Salesforce announced Headless 360, a platform that packaged Salesforce’s AI and developer tools into a headless, API-driven layer designed to help enterprise teams build agent-first workflows. It allowed AI clients like Claude or ChatGPT to read, write, and reason over Salesforce data without the traditional browser-based UI.

“It was a very popular decision among developers,” Stokes said. “Salesforce was actively endorsing people using Salesforce through an agentic interface rather than through the UI that we have had in place for 27 years.”

Developers immediately started hooking MCP servers up to their own agents. And Salesforce watched them struggle to scale their efforts.

“How do you do it for 100 or 1,000 users?” Stokes asked. “How do you deal with managed authentication to make sure it’s using the permissions of the user inside Salesforce? All the things that are necessary in order to scale this out weren’t really in place.”

Anthropic, the company behind Claude, was seeing the same thing. Its sales teams were using Salesforce through Claude and struggling to scale it. The two companies worked together to create a solution and decided to productize the result as Claudeforce.

Prebuilt sales skills and token consumption

The first fruit of the Claudeforce partnership is Salesforce in Claude, a plugin with 37 prebuilt sales skills. Stokes said these skills will enable sellers and agents to reason over live revenue context, automate pipeline updates, and take governed action within Claude. Claude-powered agents can access Salesforce data, workflows, and rules directly.

“We’ve been using it internally and so has Anthropic and some pilot customers for some time,” Stokes said. “It’s really highlighting what we think is a new way to work where the user is way faster than they’ve ever been before.”

According to Stokes, Salesforce users are leveraging Claudeforce to vibe code their own CRM interfaces, creating purpose-built command centers for how they want to run their teams. They’ve also been using it for forecasting.

“You just ask the question, and it’s going to go out and analyze the data and use its intelligence to try to tell you what to do,” he said.

He did note that customers will have to evaluate their own appetite for token consumption when it comes to leveraging Claudeforce.

“We’re starting to see early signs of what the token use looks like,” he said. “The token consumption is certainly not zero, but it is nowhere close to approaching the amount of consumption that you would find in a development use case.”

As part of the Claudeforce partnership, Salesforce is embedding Claude directly into Slack. Claude will be the default model for Slack, powering Slackbot, augmenting team decision-making via Claude Tag, and accelerating multiplayer coding through Slack Code.

The partners plan to introduce more integrations across Claude, Salesforce, and Slack over time. The Salesforce in Claude elements of Claudeforce are available to some pilot customers now and the partners said they expect to launch an open beta in September. They will launch additional prebuilt skills starting in the third quarter.

Salesforce, ServiceNow data targeted in ‘City-Forum’ attacks

Records held in Salesforce and ServiceNow systems are under attack leaving user data exposed, according to researchers at Reco.

The attack appears similar to those perpetrated by the extortion group ShinyHunters, Reco said. ShinyHunters has been particularly active this year, attacking dating sites in January and Oracle in June, and there are fears that they could have found a new target.

Reco has named the latest campaign of attacks “City-Forum,” after a domain name associated with the attackers’ IP address. While it bears similarities to Shiny Hunters’ past exploits, there are also differences. This time around the attacker penetrated the systems through the UI-API layer, an attack point that Reco had not seen used before, and had also created its own toolset to carry out the attack. It is also targeting a native ServiceNow Service Portal search endpoint that has almost no online documentation or well-known open-source tools.

The threat is particularly noteworthy, Reco said, as the attackers have studied the services to map different common data-leak vectors, a sign of an advanced approach.

A Salesforce spokesperson said that it was aware of the campaign in which malicious actors are exploiting customers’ overly permissive Experience Cloud guest user configurations in the campaign to potentially access more data than targeted organizations intended.

“This issue highlights risks stemming from misconfigurations, such as overly permissive guest user profiles, and not from a Salesforce vulnerability,” the spokesperson said.

Regardless of who the attackers were and how the attack was carried out, one thing should be clear: Organizations should be increasingly careful about who they give login credentials to.

This article first appeared on CSO.

Salesforce and SAP are putting AI agents inside your workflows. Who tells them no?

A few months ago, I was sitting in a glass-walled conference room with the executive team of a fast-growing enterprise. The vice president of customer operations was enthusiastically demonstrating the new automated agent features their software vendor had just pushed into their CRM platform.

On the screen, the software looked brilliant. The agent could read customer complaints, analyze transaction histories and automatically resolve issues. The VP showed us how the system could independently offer retention incentives to unhappy accounts without a human ever touching a keyboard.

Then I asked a simple question: “What is your approval process when the AI decides to grant a $20,000 contract discount to keep a customer from leaving?”

The room went completely silent. The VP looked at the director of IT, the director of IT looked at the chief risk officer, and everyone realized the same thing at the exact same moment. They had spent three months evaluating software licenses and security protocols, but nobody had asked who gave the software permission to sign off on corporate spending.

Major software providers like Salesforce, SAP and Oracle are rapidly moving beyond simple report writers and conversational chatbots. They are embedding active, autonomous agents directly into the transactional core of systems that manage your revenue, customer agreements and financial ledgers. According to Gartner’s latest adoption forecasts, eighty percent of enterprise applications will deploy these embedded capabilities by 2026. These applications do not just summarize data: they issue refunds, alter contract terms and trigger supply chain orders.

When I review these deployments with client teams, the core problem has nothing to do with artificial intelligence. It is a fundamental breakdown in corporate delegation and signing authority.

The breakdown of the corporate signing matrix

Every mature company I work with operates on a clear delegation of authority matrix. This framework dictates exactly who can sign off on financial commitments. A vice president might have authorization to approve spending up to $500,000, a director might sit at $100,000 and a front-line manager might be capped at $500. For two decades, technology leaders have spent millions of dollars building security and compliance controls to ensure every human employee operates strictly within those limits.

Yet when a software vendor releases an update featuring autonomous agents, companies routinely grant these features unrestricted operational freedom. Because the capability arrives as a native feature inside an existing application, business units enable it with a single click. In my advisory work, I repeatedly see organizations grant third-party software features more financial freedom than their own human managers.

This represents a massive blind spot in executive governance. McKinsey’s global surveys on artificial intelligence reveal a striking pattern across the enterprise landscape: while adoption is accelerating at a historic pace, only a tiny fraction of organizations are actively managing the financial and operational risks of automated decision errors.

The quiet cost of shadow delegation

In my audits, this rarely manifests as a dramatic system crash. It plays out as a quiet margin leak. In one organization I reviewed, a department head had enabled an automated customer retention feature over a weekend. The agent noticed an important account expressing frustration in a support ticket, and to prevent the account from churning, it independently applied an unapproved 15 percent discount to their multi-year contract.

The customer was happy, and the account manager considered the client saved. But from an executive perspective, an unvetted third-party algorithm just executed an unauthorized contract modification that eroded company margins. When the finance team conducted a quarterly audit, they did not discover an employee violating spending policy. They discovered a black-box automated decision that bypassed every internal approval control in the company.

When an auditor tests your internal controls, presenting a log showing that a vendor’s algorithm made an unauthorized financial change does not satisfy the requirement. If an action requires managerial sign-off when performed by a human being, letting software execute it independently is a major control failure.

How I advise executive teams to handle automated authority

Protecting your organization does not mean turning off these tools or falling behind on technology. It means treating vendor-supplied agents exactly like third-party contractors who have not yet passed a background check.

Forrester Research emphasizes that extending zero-trust security frameworks to automated business processes is now mandatory for enterprise risk management. Zero-trust simply means that no user, device or automated tool gets implicit trust. Every proposed action must be validated against explicit business rules before it happens.

When I help enterprise teams design these safeguards, we establish a practical three-tiered boundary for automated tools:

  • Read and draft permission: Automated tools can freely analyze trends, draft emails and assemble internal reports. No human sign-off is needed to create a draft, but the system cannot publish or execute anything on its own.
  • Standard administrative permission: Tools can handle routine administrative tasks or process standard requests below a strict financial cap (such as a $50 service credit), provided every single action is logged in an audit file that managers review weekly.
  • Restricted financial permission: Any action that alters contract terms, changes pricing tiers or issues major refunds are strictly held in an authorization queue. The system generates the request, but a human manager must click “approve” before the change hits the live database.

As a technology executive, you cannot control what automated features software providers bundle into their platforms. You can, however, control the financial boundaries and signing authority those tools are permitted to exercise within your business.

What to do at your next executive leadership meeting

  1. Ask for an automated authority inventory: Have your team audit your core software platforms to identify every automated feature currently running with permission to alter financial or customer records.
  2. Revert to draft-only mode: Instruct your team to default all vendor-supplied automated agents to “draft only” until a clear business case justifies giving them independent operational authority.
  3. Establish a firm human-in-the-loop rule: Require a strict organizational policy that no automated system can modify pricing, contracts or financial ledgers without explicit manager approval.

Agentic AI workforce is more than doubling year on year, says Salesforce

Salesforce customers more than doubled their agentic workforces year on year, according to the company’s second annual Agentic Enterprise Index, which looks at trends in AI agent development and deployment over the past five quarters.

It compiled data from customers who had activated agents in production every month of the analysis period to determine how their use of the technology has evolved between February 2025 and April 2026, as well as incorporating data from May 2026 Salesforce research studies.

It found that businesses grew their agentic workforces from an average of five agents in February 2025 to 13 by April 2026, a 7% compound monthly growth rate (CMGR). In April 2026, it only took an average of 1.9 days to deploy an agent into production, a 53% decrease since the beginning of the report period.

Not only were agents deployed more quickly, they have been progressively taking on more work once in use; over the 15 months, the average number of actions per account had a CMGR of 31%.

“These agents are expanding beyond their initial scope to really become cross-functional,” said Caila Schwartz, Salesforce’s head of agentic commerce insights, during a media briefing.

Salesforce has attempted to measure how much work agents perform, rather than how many tokens they consume, creating its own Agentic Work Unit (AWU) metric, although analysts have criticized the measure as being unrelated to business outcomes. Nevertheless, Salesforce said that as of April, Agentforce agents had performed 734 million AWUs, a number growing at about 15% each month.

The research also showed that agents are acting across multiple cloud domains which, the company said, “underscores the practical necessity of a headless architecture. By decoupling the agent’s logic from traditional front-end user interfaces, agents can process tasks, execute actions, and trigger workflows anywhere.”

Within the company, Salesforce itself has seen explosive growth in AI agent use, said Joe Inzerillo, president of enterprise & AI technology at Salesforce, with a threefold increase in sessions between February 2025 and April 2026. He said that the AI agent in Slack, Slackbot, saves the average employee five hours per week, with 83% of the company having adopted it.

But Schwartz pointed out that different industries are approaching agentic AI in different ways, some more sophisticated than others. To measure that, Salesforce developed a Sophistication Index, a five-point scale scoring the cognitive complexity of an agent’s actions. Levels 1- 3  are assigned to tasks such as record lookups, drafting emails, or summarizing documents, while levels 4 and 5 include more complex functions such as updating database fields.

The data showed that manufacturing, financial services, and healthcare and life sciences have built more sophisticated agent networks than what it called traditional AI frontrunners such as technology and retail.

However, Inzerillo said, the most common use case industry wide, and the best place to start, is the service use case, which provides “far and away the best ROI to start with.”

He also noted that, as people have become more conscious of what agents can do, they are asking agents to perform tasks, rather than simply answer questions.

“Now what you’re starting to see people do is very action oriented. So instead of asking ’how do I file a form to request my vacation’ from our employee agent, they’re telling the employee agent, ‘hey I’m taking a vacation, you need to enter this form for me, and here’s the details,’” he said, adding that this bias towards action represents the evolution of agentic use.

April 2026 Dark Web Breach Incident Trend Report

Notes the April 2026 Dark Web Breach Incident Trend Report is compiled from data breach cases posted on the deep web and dark web forums. some information is included in cases where it is difficult to fully verify the factuality of the information due to the nature of the source. Major Issues data breaches and […]

Salesforce Marketing Cloud Vulnerabilities Expose Cross-Tenant Subscriber Data Risks

Salesforce AMPScript

A recently disclosed set of vulnerabilities in Salesforce Marketing Cloud, widely known as SFMC, has drawn attention to the security risks tied to centralized marketing infrastructure.   The flaws, which affected components tied to AMPScript, CloudPages, and email-rendering workflows, could have enabled attackers to access subscriber information, enumerate marketing emails, and potentially affect organizations across multiple tenants.  Security researchers found that weaknesses in SFMC’s templating engine and cryptographic implementation introduced opportunities for unauthorized data access across customer environments. 

AMPScript and SFMC Template Injection Risks 

Modern enterprises rely heavily on Salesforce Marketing Cloud to manage large-scale marketing campaigns, personalized customer journeys, and trackable email communications. The platform, formerly known as ExactTarget, supports dynamic content generation through technologies such as AMPScript, Server-Side JavaScript (SSJS), and internal data views connected to large subscriber databases.  While these features provide flexibility for marketers, researchers noted that they also increase the impact of any underlying vulnerability. One of the major concerns centered on SFMC’s server-side templating framework.  AMPScript and SSJS allow organizations to dynamically insert subscriber attributes such as names, email addresses, and engagement metrics directly into marketing content. However, functions like TreatAsContent introduced a dangerous behavior because they effectively evaluate user-controlled input as executable template code. Researchers explained that if attacker-controlled data was passed into these functions, it could trigger template injection inside Salesforce Marketing Cloud environments.  The issue became more severe because SFMC historically supported AMPScript execution within email subject lines. According to the findings, legacy behavior caused subject templates to be evaluated twice by default. That design opened the door for payload execution during the second rendering stage. Researchers demonstrated the risk using the following payload inside a name field:  %%=RowCount(LookupRows("_Subscribers","SubscriberKey",_subscriberkey))=%%  If processed during the second evaluation phase, the payload could execute successfully and create a reliable injection point inside the marketing workflow.  Once template execution was achieved, attackers could potentially use built-in SFMC functions such as LookupRows to query internal Data Views, including: 
  • _Subscribers  
  • _Sent  
  • _Job  
  • _SMSMessageTracking  
  • _Click  
Access to these views could expose subscriber lists, email delivery records, engagement metrics, and message history associated with affected Salesforce Marketing Cloud tenants. 

CloudPages and “View Email in Browser” Vulnerability

Researchers identified an even more serious vulnerability tied to SFMC’s “view email in browser” functionality and CloudPages infrastructure. Many Salesforce customers configure branded domains such as view.example.com or pages.example.com that route back to shared SFMC infrastructure. These links typically rely on an encrypted qs parameter containing tenant and message-specific information. According to researchers from Searchlight Cyber, the older “classic” qs implementation used unauthenticated CBC encryption. The researchers found that the implementation behaved as a padding oracle, which made it possible to decrypt and re-encrypt query string parameters under certain conditions. Initially, the researchers abused the weakness using the Padre tool before later improving the process through the AMPScript MicrositeURL function.  This allowed them to forge valid QS values and access workflows such as “Forward to a Friend,” which could resolve subscriber identifiers into actual email addresses.  One of the most concerning aspects of the vulnerability was SFMC’s use of a single static encryption key shared across tenants. Researchers stated that once the cryptographic structure became understood, attackers could theoretically enumerate subscribers and access email content across multiple organizations using the same mechanism.

Legacy Encryption Weaknesses Expanded the Attack Surface 

The researchers also uncovered an older URL format that relied on per-parameter “encryption.” However, the mechanism reportedly consisted of a repeating static XOR key combined with a checksum. Although the scheme was considered legacy functionality, researchers found that it still worked on modern SFMC tenants. Because the implementation lacked strong cryptographic protections, attackers could decrypt and enumerate parameters such as JobID and ListSubscriber at high speed without relying on the slower padding-oracle technique.  The findings highlighted how legacy systems inside large cloud platforms can continue to create security exposure long after newer protections are introduced. 

Impact of the Salesforce Marketing Cloud Vulnerability 

Researchers concluded that the combined vulnerabilities could have enabled attackers to: 
  • Enumerate and exfiltrate subscriber records  
  • Access sent marketing emails and engagement data  
  • Forge cross-tenant QS tokens  
  • Access emails belonging to other organizations  
  • Exploit hard-coded cryptographic material  
  • Abuse argument-injection flaws tied to the MicrositeURL function  
  • Manipulate CloudPages and other SFMC web workflows  
To address the issues, Salesforce assigned multiple CVEs covering several root causes, including insecure cryptographic implementations, hard-coded keys, and argument injection vulnerabilities affecting MicrositeURL and CloudPages components.  According to Salesforce, the vulnerabilities were reported on 16 January 2026. Mitigations were deployed between 21 January and 24 January 2026. The company stated that it had identified no confirmed malicious exploitation at the time of disclosure.  As part of the remediation process, Salesforce migrated Marketing Cloud Engagement encryption to AES-GCM, rotated encryption keys, and disabled the double evaluation behavior tied to AMPScript subject-line rendering.  The company also invalidated all legacy tracking and CloudPages links created before 21 January 2026 at 23:00 UTC. Those links expired globally on 23 January 2026 at 21:00 UTC. 

Ransom & Dark Web Issues Week 4, April 2026

ASEC Blog publishes Ransom & Dark Web Issues Week 4, April 2026           ShinyHunters Claims Data Breach Involving Major U.S. Convenience Store Chain ShinyHunters Claims Theft of Internal Data and Source Code from U.S. Software Development Firm Emergence of New Data Extortion Group: Prinz Eugen

March 2026 Dark Web Breach Trends Report

Alerts this report is based on reports of data breaches and the sale of initial access rights posted on deep web-dark web forums. some parts of the report contain information that cannot be fully verified as factual due to the nature of the source. Major Issues Multiple breach claims by ShinyHunters. a wide range of […]
❌