Tools
2026-08-06
Atlassian's Rovo AI can be tricked into leaking Jira and Confluence data — with zero clicks
Security firm PromptArmor published a zero-click attack that makes Rovo, Atlassian's workplace AI assistant, exfiltrate anything it can read — Jira tickets, Confluence pages, connector data — by hiding instructions in content the assistant later processes and having it open an attacker's URL with the stolen data appended. PromptArmor says it disclosed the flaws on May 23, and that more than two months later Rovo remained vulnerable, with the leak working even when an organization disables web search. A separate one-click bug using crafted Rovo chat links, reported by another researcher, has been fixed server-side.
Why it mattersEvery company wiring an AI assistant into its wiki, tickets and email creates the same shape of hole: the assistant reads attacker-controlled content with employee privileges and holds a tool that can call out. Millions of teams run Atlassian — and a disclosure sitting unpatched for ten weeks is exactly what security researchers mean when they say prompt injection remains unsolved.
✓ Verified · 2 sources
Read in the app — free, in 9 languages
Related stories
Apple Music will tell you when a song was made by a machine — but the uploader decides whether to say so
2026-08-21DeepSeek's cheap workhorse can now see — and on agent tasks that need eyes it says it is close to Anthropic's best
2026-08-21Stripe has just paid $7.5 billion for a model router. Days later Ramp built one and is giving it away until January.
2026-08-21Meta's assistant is now a Mac app that reads your screen and types into any window — and what it sees can train the model
2026-08-21One click on a news site now tells Google to show you more of it — and you stay on the page you were reading
2026-08-21