Cybersecurity3 min reading time

Atlassian Rovo Exfiltrates Data, Bypassing Controls

Hacker News
Read full post
Security researchers PromptArmor disclosed vulnerabilities in Atlassian's Rovo AI that allow attackers to exfiltrate Jira tickets and Confluence documents without user approval by exploiting Rovo's URL retrieval tool. Despite disclosure in May, Atlassian has not addressed the issue, leaving Rovo vulnerable to indirect prompt injection attacks that bypass web search disabling.

More on this story


More in Cybersecurity

Cybersecurity10 min read

Anthropic Details Disrupted Claude Misuse Across Seven Harm Areas

Covered by 4 sources
Cybersecurity4 min read

Sam Altman met with top power utilities about securing the electrical grid. He offered one possible solution: OpenAI's cyber services.

Covered by 2 sources
Cybersecurity6 min read

Anthropic reveals rogue AI agents hate CAPTCHAs, just like you

TechCrunch