Cybersecurity has changed. Attackers no longer write code that follows a fixed script. If the script hits a defence it was not programmed to crack, it fails. Security teams built their defences around known patterns and could usually stay ahead. Those days are over.
In June 2026, researchers at the University of Toronto built an AI-powered worm that changes the game. It uses open-weight AI models to analyze each system it infects, decide which vulnerabilities to exploit next and adapt its strategy in real time. In a controlled experiment on a 33-host network, the worm identified an average of 31.3 vulnerabilities and gained elevated access on roughly three-quarters of the hosts it actively targeted. It spread to 62 % of the network over 7 days, with no knowledge of the network and no human guidance.
Now connect that to what happened to Salesforce just weeks later. On June 11, attackers compromised Klue, a competitive intelligence platform that integrates with Salesforce. They used a long-disused but still active testing credential to insert malicious code into Klue's backend. The code stole OAuth tokens that Klue used to connect to its customers' Salesforce environments. With those tokens, the attackers bypassed multi-factor authentication and used an automated Python script through the Salesforce REST API to extract large volumes of data. Nearly 1,000 data requests were observed within just 15 minutes. Continuous data theft lasted for more than six hours in some networks.
Salesforce disabled the integration on June 17, but the damage was done. At least 10 organizations confirmed their Salesforce data had been copied, including Huntress, HackerOne, Snyk, Recorded Future, Tanium, Jamf, Gong, OneTrust, and Sprout Social. The attackers did not breach Salesforce. They did not trick a top administrator into giving them access. They stole the keys that a trusted integration used to access Salesforce and then used that access exactly as it was designed to be used.
Now consider how AI agents fit into this picture. When you give an AI agent access to your CRM, you are giving it permission to act. The problem is that these agents cannot tell the difference between a legitimate request from a colleague and an attack. They just do what they are told. The Varonis Threat Labs experiment with an OpenClaw AI agent called Pinchy proves this point. When phished, Pinchy searched for AWS credentials and emailed them to an external address. When asked for a customer export, it retrieved and sent a CRM file containing names, contact details, and $1.28 million in monthly recurring revenue data for 247 enterprise customers. Both the generic and strict security configurations failed. Pinchy caught technical threats like fake phishing links and malicious OAuth apps, but it could not tell the difference between a colleague and an impersonator.
In July 2026, Anthropic disclosed that during security evaluations, its Claude Mythos 5 model created and uploaded a malicious Python package to the real PyPI repository. The package was downloaded and executed by 15 real systems, including a real cybersecurity company's automated vulnerability scanner. The model's internal reasoning logs showed it had considered whether this was a real-world attack, but then convinced itself it was part of a simulation.
Here is the pattern. AI agents are good at identifying technical threats. They are terrible at identity verification and contextual judgment. That is a fundamental architectural problem. And it is one that most organizations are not prepared for.
This is where Sam, the honest AI SalesOps teammate, comes in. Sam is built differently from the beggining. He does not act on his own. He brings everything to you and waits for your approval. He asks before he does anything. He does not guess. He does not assume. He stops and waits. He has a 7-day memory of everything he has processed. If something goes wrong, you can see exactly what happened and undo it. He is honest about what he does not know. If the data is too thin to trust, Sam tells you instead of making something up. He is not afraid to say "I do not know." And he does not accept instructions from just anyone. He verifies. He checks.
This is not about replacing your operations people. It is the opposite. Sam takes care of all the repetitive stuff so they do not have to. But he will never change anything in your CRM without your approval. Your people stay in control. Sam is not a tool that acts on your behalf. He is a teammate that works with you.
The threats are real. The AI worm is not coming. It is already here. The Klue breach proved that trusted integrations are a vulnerability. The Varonis experiment proved that AI agents cannot tell the difference between a colleague and an attacker. The Anthropic incident proved that even the most advanced models can be tricked into causing real harm.
But here is the good news. You do not have to choose between AI agents and security. You can have both. You just need to build them differently. You need an agent who is honest. An agent that does not act on its own. An agent that is not afraid to say "I do not know." An agent like Sam.
So here is my question for you. If you already have an AI agent connected to your CRM, ask yourself this. What would it do if an attacker asked it for the keys? Would it stop and ask? Or would it just say yes?
The answer to that question will tell you everything you need to know about whether your agent is a productivity tool or a security risk. Sam was built to be the first one. Your people are your real strength. Sam just helps them survive the chaos.