LIVE · cybersecurity feed
Live wire
atlassianhigh

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Two security firms have identified vulnerabilities in Atlassian's Rovo assistant that could allow attackers to exfiltrate data from Jira and Confluence. One vulnerability, dubbed RovoBlast by Varonis Threat Labs, allowed attackers to trick Rovo into sending data to an external server via a malicious link. Atlassian has confirmed this issue is fixed server-side. The second vulnerability, found by PromptArmor, involved injecting malicious instructions into content Rovo processes, enabling data exfiltration without explicit user approval. The status of this second vulnerability remains unconfirmed after its initial disclosure.

zeroday.news ·

Reports indicate that Atlassian's Rovo assistant has been found to contain vulnerabilities that could be exploited to exfiltrate sensitive data from Jira and Confluence instances. Two separate security firms have identified distinct mechanisms by which an attacker might trick Rovo into disclosing information. These findings highlight potential security risks associated with AI-powered assistants that interact with enterprise data.

One of the identified vulnerabilities, named "RovoBlast" by Varonis Threat Labs, reportedly involved manipulating Rovo into transmitting data to an external server. This was achieved by leveraging a malicious link, suggesting a potential for social engineering or content injection to direct Rovo's actions. Atlassian has acknowledged this specific issue and stated that it has been addressed with a server-side fix, implying that users do not need to take direct action to mitigate this particular vulnerability.

The technical mechanism behind RovoBlast likely involved Rovo's processing of external URLs or content that contained instructions to retrieve and then forward internal data. AI assistants, by design, often interact with various data sources and can be programmed to follow links or process content. If not properly sanitized or restricted, these capabilities can be abused to bypass typical access controls, especially if the assistant operates with elevated permissions or a broad scope of access to internal systems like Jira and Confluence.

A second, distinct vulnerability was reportedly discovered by PromptArmor. This issue involved injecting malicious instructions directly into content that Rovo processes. Unlike RovoBlast, which leveraged external links, this method appears to exploit how Rovo interprets and acts upon internal data or user-provided text. The report indicates that this could lead to data exfiltration without requiring explicit user approval, suggesting a potential for a more stealthy or automated attack.

The nature of this second vulnerability points towards a prompt injection or similar technique, where specially crafted input within a document or message can trick the AI into performing unintended actions. This class of vulnerability is common in large language models and AI assistants, where the model's ability to understand and generate human-like text can be co-opted to execute commands or reveal information it has access to. The status of this second vulnerability, following its initial disclosure, remains unconfirmed in the reports.

For vulnerabilities of this type, typical mitigation strategies often involve robust input validation and sanitization, ensuring that AI models do not execute arbitrary commands embedded in user-controlled data. Implementing strict access controls and least privilege principles for AI assistants, limiting their ability to access or transmit sensitive data without explicit, verified authorization, is also crucial. Regular security audits and penetration testing of AI-powered systems are essential to uncover and address such flaws.

These findings underscore the evolving security landscape introduced by the integration of AI assistants into enterprise environments. As AI tools gain access to vast amounts of organizational data and capabilities, the potential attack surface expands. Organizations deploying such technologies must remain vigilant about novel attack vectors, particularly those that exploit the unique characteristics of AI, such as prompt injection and the processing of untrusted external content.

atlassianrovojiraconfluenceprompt injection
ShareXLinkedInWhatsAppFacebook

More News

view all →
breachcritical

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data. The post Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data appeared first on SecurityWeek.

surveillance

Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed

Flock Safety, a company known for its public safety cameras, reportedly pitched a plan to utilize dashcams from rideshare and delivery vehicles to collect license plate data. This initiative, which did not proceed, would have involved a partnership with Nexar, a dashcam manufacturer, and potentially involved drivers without their knowledge. Separately, a former Flock employee alleged the company provided direct camera access to ICE and CBP through a pilot program, contradicting internal statements.

email securityhigh

Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All

Security researchers Cory Solovewicz and Mike Sheward have inadvertently created honeypots by purchasing domains like noreply.us and deleteduser.com. Organizations are mistakenly sending sensitive data, including personal information, company secrets, and system credentials, to these domains, believing they are unmonitored. Both researchers are now working to notify affected entities and raise awareness about this widespread misconfiguration, highlighting the potential for malicious actors to exploit such vulnerabilities.

css attackshigh

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

New research reveals that sophisticated CSS-based attacks can bypass webmail security measures, enabling attackers to steal sensitive information like passwords and session tokens. These techniques exploit vulnerabilities in popular email services including Outlook, Gmail, and Yahoo Mail, potentially leading to account takeovers and data breaches. The findings highlight the need for stricter sanitization and isolation of email content.

breach

Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients

Hackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems’ data center. Unlimited Technology Systems disclosed a data breach affecting more than 3.8 million people after hackers accessed one of its commercial data centers between October 5 and 10, 2025. Unlimited Technology Systems is a U.S.-based healthcare technology company headquartered […]

CVE-2023-38646critical

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase has issued a critical alert regarding a zero-day vulnerability in its business intelligence software that has been actively exploited. The flaw allows unauthenticated attackers to inject SQL, leading to administrator access, credential theft, and data exfiltration. Metabase Cloud instances have been patched, and users of self-hosted versions are urged to update immediately.