AnalysisCybersecurityAugust 10, 2026

Hidden PDF text can hijack Atlassian's Rovo AI assistant

Read original source →decrypt.co

PromptArmor says Atlassian's Rovo can be steered to exfiltrate Jira tickets and Confluence docs via hidden instructions in uploaded PDFs — a zero-click attack with no approval prompt. It works even when web search is disabled, since the URL-opening tool stays live. Atlassian got the report on May 23 but Rovo 'remains vulnerable,' the firm says.

1 source

More stories today

Open the live feed