Kryptovalutaticker:
sysadmin från Cyber Security News

Atlassian Rovo Prompt Injection Exfiltrates Jira and Confluence Data Without User Approval

Abinaya
4 hours ago
7 Visningar
0 Kommentarer
Atlassian Rovo Prompt Injection Exfiltrates Jira and Confluence Data Without User Approval

RovoBlast is a one-click prompt-injection vulnerability in Atlassian Rovo that could allow attackers to exfiltrate sensitive enterprise data from Jira, Confluence, SharePoint, and other connected services. Atlassian addressed the reported URL-based issue on the server side after responsible disclosure, with the fix deployed on July 8, 2026. Rovo is Atlassian’s enterprise AI assistant, designed to search, summarize, and take actions across Jira, Confluence, Bitbucket, and third-party SaaS platforms. Its value comes from access to organizational context. However, the same broad access can create a major security risk when attacker-controlled content is treated as trusted instructions. The RovoBlast attack abused a URL parameter...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!