CybersecurityDev6 min reading time

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

The Hacker News
Read full post
Two security firms independently discovered that Atlassian's Rovo assistant can be manipulated to extract Jira and Confluence data accessible to a signed-in user and send it to external servers. One vulnerability, involving a URL parameter, has been fixed server-side, while another, using embedded instructions in uploaded content, remains partially unconfirmed as remediated. These flaws allow attackers to exploit Rovo without explicit user approval, posing data exfiltration risks.

More on this story


More in Cybersecurity

Cybersecurity10 min read

Anthropic Details Disrupted Claude Misuse Across Seven Harm Areas

Covered by 4 sources
Cybersecurity4 min read

Anthropic blocks 'malicious use' of AI that could develop biological weapons

BBC
Cybersecurity4 min read

Sam Altman met with top power utilities about securing the electrical grid. He offered one possible solution: OpenAI's cyber services.

Covered by 2 sources