Hidden Text Hijacks Atlassian Rovo AI Agent to Steal Data

TL;DR. PromptArmor identified a prompt injection vulnerability allowing hidden text in PDFs to hijack Atlassian's AI agent, Rovo, for sensitive data exfiltration. - The attack uses concealed instructions in documents, enabling Rovo to silently transmit internal Jira and Confluence data. - This vulnerability requires no user confirmation and leaves no visible traces, making detection difficult for users. - The security flaw highlights ongoing challenges with prompt injections in AI systems, affecting enterprise tools like Rovo.

Sources

Back to QLANKR News