Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

August 10, 2026

Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant

August 10, 2026

Are AI tutoring tools safe for your kids?

August 10, 2026
Facebook X (Twitter) Instagram
Monday, August 10
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant
Cyber Security

Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant

Team-CWDBy Team-CWDAugust 10, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A flaw in Atlassian’s enterprise AI assistant has allowed a single crafted link to seed attacker instructions into a victim’s authenticated session, then use the assistant’s own browsing agent to push company data out to the public web.

Varonis Threat Labs disclosed the flaw, which it named RovoBlast, to Atlassian and published its analysis on August 7 after presenting the research at DEF CON 34. Atlassian has since fixed it.

Rovo functions as an AI layer across Jira, Confluence and Bitbucket, alongside connected services including Slack, Microsoft 365 and Google Workspace.

Asked to enumerate what it could read, it listed all of those plus relational databases, uploaded files, web pages and archives. Atlassian’s connector catalogue supports more than 50 platforms.

Read more on AI assistant data leakage: New Zero-Click AI Vulnerability Allows Corporate Data Theft

A Prompt Delivered in the URL

Rovo accepted a URL parameter that pre-filled its chat entry, surfacing whatever the link contained directly into the session. Varonis called the pattern Parameter-to-Prompt, and identified the same primitive in Microsoft Copilot in January under the name Reprompt.

Because the victim’s session was already held in the browser, a click was all that was required. No warning appeared, no confirmation was requested, and nothing marked the session as having been seeded from an external parameter.

The organization identifier in the path could also be left empty, with Atlassian redirecting the request into the user’s default organization.

Varonis described Rovo’s guardrails around untrusted prompts as “almost non-existent,” and said one click was usually enough to have the assistant retrieve and summarize sensitive material without any bypass technique.

The Assistant’s Own Research Tool as the Exit

Turning that access into leakage required an outbound path, and Varonis found one already built in. Rovo’s ResearchAgent performs multi-source open web research and can browse and navigate arbitrary websites across multiple steps autonomously.

That combination supplied the whole chain in a single agent run: retrieve internal content, transform it, then post it somewhere externally reachable. Chaining the steps inside one agent also reduced the number of user-facing interactions, leaving an audit trail that resembled ordinary research activity.

Compounding the exposure, Rovo cannot be fully removed from an Atlassian environment, so organizations cannot eliminate the attack surface by uninstalling it.

Varonis recommended shrinking what the assistant can reach, disconnecting unused integrations and keeping legal, HR, finance and incident response content out of scope entirely.

It also advised disabling browsing agents and multi-step automation where teams do not rely on them, reviewing assistant logs, alerting on unusual agent runs and periodically testing how an environment responds to seeded prompts.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAre AI tutoring tools safe for your kids?
Next Article New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
Team-CWD
  • Website

Related Posts

Cyber Security

Addressing Vulnerability Management Together in the Age of AI

August 7, 2026
Cyber Security

Toolkit Hidden Inside Oracle Database Evades Endpoint Tools

August 6, 2026
Cyber Security

Paperclip AI Flaws Let Unauthenticated Attackers Run Commands

August 5, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

In memoriam: David Harley

November 12, 2025

Find your weak spots before attackers do

November 21, 2025

2025’s most common passwords were as predictable as ever

January 21, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.