Security researchers have exposed critical prompt injection vulnerabilities in Atlassian's Rovo AI assistant that allow silent data exfiltration from Jira and Confluence. PromptArmor revealed that attackers can hide invisible commands in uploaded PDFs to force Rovo to transmit sensitive data to external servers. Although Atlassian patched a separate vulnerability reported by Varonis on July 8, 2026, the firm has not patched PromptArmor's May 23 disclosure, leaving Rovo actively vulnerable.
Aug 10, 2026 · 1 source
Aug 10, 2026 · 3 sources
Aug 10, 2026 · 8 sources
Aug 9, 2026 · 9 sources
Story comments
Loading comments…