S&P 5007,709.96▼0.2% Nasdaq26,348.35▼0.1% Dow53,885.10▼0.8% Russell 2K3,001.55▼0.6% 10-Yr4.67%+5bp VIX15.15−0.66 WTI$78.07▲3.8% Gold$4,292.00▲1.1% EUR/USD1.152▼0.3% BTC$64,046▼1.2% Nikkei65,101▼1.8%
At close · Fri, Aug 7, 2026
Daily Market Updates.

Crypto

HomeCryptoRegulationPrompt injection can hijack Atlassian Rovo to exfiltra…

Prompt injection can hijack Atlassian Rovo to exfiltrate data

The attack can work without any approval click, even if an organization disables Rovo web search, because the URL-opening tool remains available.

PromptArmor says Atlassian's Rovo AI assistant can be manipulated to steal data from Jira and Confluence through hidden instructions embedded in uploaded files like PDFs. The firm describes it as a zero-click approach, where the poisoned file carries concealed prompts that the agent treats as legitimate commands.

The security company says the technique can cause Rovo to gather sensitive tickets and docs and then paste the information onto an attacker-controlled URL. It notes the method can succeed even when Rovo's web search is disabled, because the setting does not remove the tool that opens search results.

PromptArmor also frames the issue as a modern version of how black-hat actors previously hid content from users while making it readable to machines. In Rovo's case, text planted in documents and invisible to the human eye is still recognized by the agent as instructions.

Atlassian reportedly received the disclosure on May 23 and did not publicly respond further for two months, during which PromptArmor says Rovo remains vulnerable. The report is based on the risk that AI agents that read and act across enterprise workspaces can be turned into a data pipeline with a single poisoned file.

More like this

Sources

Get the close, explained.

One email every trading day: what moved, why it moved, and what's on deck tomorrow. Read in 3 minutes.

Free. Unsubscribe anytime.