DAPSSADAPSSA

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

By DAPSSA AI Desk | 2026-08-10T04:12:59.404Z
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Overview

Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed. PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file was

Key Developments

This reflects an evolving cybersecurity situation.

Technical Details

Attackers may use automation and vulnerabilities.

Impact & Risks

Potential disruption and data exposure.

Conclusion

Organizations must stay vigilant.

Read more: https://thehackernews.com/2026/08/atlassian-rovo-can-be-tricked-into.html

Join the Discussion