SECURITYTHE HACKER NEWS
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Atlassian's Rovo assistant can be exploited using attacker-controlled instructions to collect Jira or Confluence data accessible to a signed-in user, and then send this data to an outside server. The vulnerability was independently discovered by two security firms; PromptArmor identified that the malicious instructions were hidden within content that Rovo reads.
Related Signal