AnalysisCybersecurityAugust 10, 2026

Hidden PDF text can hijack Atlassian's Rovo AI assistant

PromptArmor says Atlassian's Rovo can be steered to exfiltrate Jira tickets and Confluence docs via hidden instructions in uploaded PDFs — a zero-click attack with no approval prompt. It works even when web search is disabled, since the URL-opening tool stays live. Atlassian got the report on May 23 but Rovo 'remains vulnerable,' the firm says.

1 source

Daily brief

Get tomorrow's AI brief in your inbox

More stories today

Open the live feed
Hidden PDF text can hijack Atlassian's Rovo AI assistant — AIBriefs