LIVE · cybersecurity feed
Live wire
OpenAI locks down Astra over potential critical cyber capabilitiesCritical Flaws Discovered in Belgian eID Software Used by 2 Million PeopleSecurity Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITIONWebmail CSS Attacks Expose a New Risk for AI-Powered Email ToolsMetabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataCVE-2026-8037 · CISA Adds Progress LoadMaster Command Injection Flaw to KEV CatalogSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
vulnerability

Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant

Atlassian fixed a flaw letting one crafted link make its Rovo AI assistant exfiltrate company data

zeroday.news ·

A vulnerability, dubbed "RovoBlast" by Varonis Threat Labs, was discovered in Atlassian's enterprise AI assistant, Rovo, allowing for the exfiltration of company data through a single crafted link. The flaw was disclosed to Atlassian by Varonis, which published its analysis on August 7 after presenting the research at DEF CON 34. Atlassian has since confirmed and fixed the issue.

Rovo functions as an AI layer integrated across Atlassian products like Jira, Confluence, and Bitbucket, and also connects to services such as Slack, Microsoft 365, and Google Workspace. The assistant is capable of accessing and summarizing content from these platforms, as well as relational databases, uploaded files, web pages, and archives, with Atlassian's connector catalog supporting over 50 platforms.

The core of the RovoBlast vulnerability lies in a "Parameter-to-Prompt" mechanism, where Rovo accepted a URL parameter that pre-filled its chat entry with attacker-controlled instructions. This meant that a victim, already authenticated in their browser, only needed to click a specially crafted link. No warning or confirmation was presented to the user, and the session was not marked as having been initiated from an external parameter. Varonis noted that the organization identifier in the URL path could even be left empty, with Atlassian redirecting the request to the user's default organization.

Varonis characterized Rovo's safeguards against untrusted prompts as "almost non-existent," observing that a single click was typically sufficient for the assistant to retrieve and summarize sensitive material without requiring any bypass techniques.

To facilitate data leakage, Varonis identified an existing outbound path within Rovo: its "ResearchAgent." This agent is designed for multi-source open web research and can autonomously browse and navigate arbitrary websites across multiple steps. This functionality allowed for a complete attack chain within a single agent run: retrieve internal content, transform it, and then post it to an externally accessible location. Chaining these steps within one agent also minimized user-facing interactions, resulting in an audit trail that resembled ordinary research activity.

Compounding the exposure, Rovo cannot be fully uninstalled from an Atlassian environment, meaning organizations cannot eliminate the attack surface by removing the assistant entirely.

Varonis recommended several mitigation strategies. These include limiting the scope of what the assistant can access, disconnecting unused integrations, and explicitly excluding sensitive content from legal, HR, finance, and incident response departments from Rovo's reach. Additionally, Varonis advised disabling browsing agents and multi-step automation where they are not essential, regularly reviewing assistant logs, configuring alerts for unusual agent runs, and periodically testing how an environment responds to seeded prompts.

vulnerabilitypatchai
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Metabase zero-day exploited to access Framework customer data

Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day vulnerability in the Metabase business intelligence service. According to the notification sent to affected Framework customers, the attackers accessed names, email addresses, phone numbers, physical addresses, and login IP addresses,

security

Poland uncovers second heat plant cyberattack that went hidden for months

The incident occurred on the same day as coordinated cyberattacks struck more than 30 other renewable energy installations and a larger heat plant, as Poland publicly disclosed in January.

security

Senate Democrats introduce bill to distribute $300 million annually to shore up water system cybersecurity

Two Democratic senators introduced legislation that would allocate $300 million each year to fund cybersecurity improvements for the water and wastewater sector.

security

UK man tied to The Com sentenced for abusing 117 victims

Justin Swaddle, who was a minor when he committed the crimes, coerced children across multiple countries into self-harm and sexual abuse using threats tied to their personal information, authorities said. The post UK man tied to The Com sentenced for abusing 117 victims appeared first on CyberScoop.

security

Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification

Cisco is proud to announce a landmark achievement: Secure Email Threat Defense has officially achieved FedRAMP Class D (High) certification!

breach

Cyberattack on Steam hardware shipper leaks names, addresses, and order data

Video game publisher Valve is alerting customers in Europe to a data breach at CEVA Logistics, its Steam hardware shipping partner. Reports from affected customers began surfacing on social media earlier today, after Valve started sending out data breach notification emails. “Between July 29 2026 and August 1, 2026, a cyberattack hit CEVA Logistics, the company that ships Steam hardware to custome