Tools
AI Minute Newsroom
2026-08-06
Atlassian's Rovo AI can be tricked into leaking Jira and Confluence data — with zero clicks
Security firm PromptArmor published a zero-click attack that makes Rovo, Atlassian's workplace AI assistant, exfiltrate anything it can read — Jira tickets, Confluence pages, connector data — by hiding instructions in content the assistant later processes and having it open an attacker's URL with the stolen data appended. PromptArmor says it disclosed the flaws on May 23, and that more than two months later Rovo remained vulnerable, with the leak working even when an organization disables web search. A separate one-click bug using crafted Rovo chat links, reported by another researcher, has been fixed server-side.
Why it mattersEvery company wiring an AI assistant into its wiki, tickets and email creates the same shape of hole: the assistant reads attacker-controlled content with employee privileges and holds a tool that can call out. Millions of teams run Atlassian — and a disclosure sitting unpatched for ten weeks is exactly what security researchers mean when they say prompt injection remains unsolved.
✓ Verified · 2 sources
Read in the app — free, in 9 languages
Related stories
Meta's assistant keeps an hourly file on everyone in your life.
2026-10-05Two senators want prison time for bosses whose AI agents hack.
2026-10-05One command restores the Apple Intelligence off switch Apple deleted.
2026-10-05OpenAI will ship a Codex upgrade daily for 28 days or reset limits.
2026-10-05Untuned models solved agent tasks their polished versions could not.
2026-10-04