Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Hackers breach TrueConf to trojanize client installers with backdoors

    August 8, 2026

    This $1.5 billion hack is exposing just how ‘irreversible’ stolen crypto really is

    August 8, 2026

    Does this video show SpaceX rocket crashing into the moon?

    August 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Hackers breach TrueConf to trojanize client installers with backdoors
    • This $1.5 billion hack is exposing just how ‘irreversible’ stolen crypto really is
    • Does this video show SpaceX rocket crashing into the moon?
    • As Thailand Gets Known for Mass Shootings, Fresh Pledges to Fix Gun Laws
    • Census Proposal Would Stop Counting Undocumented Immigrants—and Ignore Race and Sexual Orientation
    • Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data
    • XRP at a Crossroads as Senate Punts on Clarity Act
    • Alabama Seeks to Lower Gas Utility Profits for the First Time in 40 Years
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 8, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    DEF CON — Varonis Threat Labs has disclosed a one-click vulnerability in Rovo, Atlassian’s enterprise AI assistant, that let a specially crafted link seed attacker-controlled instructions directly into a user’s live AI session. 

    Dubbed RovoBlast, the flaw required no jailbreak and no permission bypass, relying on the fact that the assistant simply treated externally supplied parameters as trusted input.

    Rovo functions as an AI layer spanning Jira, Confluence, Bitbucket, and third-party tools such as Slack, Microsoft 365, and Google Workspace. It also carries autonomous agent features capable of completing multi-step tasks with no further user involvement, which is what enabled the RovoBlast attack. 

    [ Read: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones ]

    The exploit leveraged a URL parameter called rovoChatPrompt, which pre-fills content straight into Rovo’s chat window. Varonis researchers describe this attack path as parameter-to-prompt (P2P) injection, which they previously reported in Microsoft Copilot as Reprompt in January. 

    Researchers noticed that the organization ID part of the URL could be left blank and Atlassian would still route the request into the victim’s own default organization, all without any warning or indicator that the session had been seeded by an outside source.

    Advertisement. Scroll to continue reading.

    To gauge the potential blast radius, the researchers simply asked Rovo what data it could see. The AI’s answer included Jira, Confluence, Bitbucket, Slack, Google Workspace, Microsoft 365, relational databases, uploaded files, web pages, and archived content.

    The actual leakage came from ResearchAgent, one of Rovo’s built-in tools, which can autonomously conduct multi-source web research and navigate across arbitrary sites. Once an attacker’s prompt was seeded through the malicious link, that same capability let Rovo pull internal data and push it out to the open web in a single automated chain. 

    The team demonstrated the technique in three separate proof-of-concept scenarios: exfiltrating Confluence pages, Jira tickets, and SharePoint content containing personal data.

    Notably, the researchers found that a single seeded link was generally enough to trigger the leak. The attack didn’t require chaining multiple requests or any additional bypass steps to get Rovo to retrieve and summarize sensitive data.

    Varonis disclosed RovoBlast to Atlassian, which fixed the issue before the findings were published.

    The researchers recommend that organizations limit which systems Rovo can reach, disconnect unused integrations, wall off sensitive areas such as legal, HR, and finance, disable browsing or multistep automation features that aren’t in active use, and pair this with routine monitoring of assistant activity logs.

    An Atlassian spokesperson provided the following statement to SecurityWeek:

    The security of our customers’ data is our highest priority. We are working with customers to implement protective controls on their instances. This is an ongoing and evolving responsibility, and we are actively working on and investing in additional solutions.  

    For the vulnerability to be exploited, a user with access to a customer’s Atlassian instance must provide untrusted content with a prompt injection to Rovo. This is a class of attack that affects AI systems across the industry. Similar to any phishing-type attack, we recommend customers follow security best practices and verify that any content provided to their Atlassian apps comes from a trusted source.

    Varonis presented the research at DEF CON 34 on Friday. A technical write-up is available on the Varonis blog.

    Related: Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts

    Related: Meta AI Hacked External Systems During Cybersecurity Testing

    Related: Atlassian, Splunk Patch Critical Vulnerabilities

    Atlassians critical data enterprise exposed OneClick Rovo Vulnerability
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hackers breach TrueConf to trojanize client installers with backdoors

    New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

    Déjà Vu? Meta’s AI Escapes Testing Lab in Hacking Joyride

    Swiss government SharePoint breach compromised 200 accounts

    Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

    Bitcoin Payment Service BTCPay Warns Critical Flaw Is Under Active Attack

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Hackers breach TrueConf to trojanize client installers with backdoors

    August 8, 2026

    This $1.5 billion hack is exposing just how ‘irreversible’ stolen crypto really is

    August 8, 2026

    Does this video show SpaceX rocket crashing into the moon?

    August 8, 2026

    As Thailand Gets Known for Mass Shootings, Fresh Pledges to Fix Gun Laws

    August 8, 2026
    Latest Posts

    With Hopes High for New H.I.V. Prevention Pill, Merck Takes Steps to Ensure Access

    July 24, 2026

    Trump to speak at rescheduled White House Correspondents’ Dinner following failed April shooting

    July 24, 2026

    When is an apology not an apology? When it comes from an AI boss with an out-of-control chatbot | Marina Hyde

    July 24, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Hackers breach TrueConf to trojanize client installers with backdoors

    August 8, 2026

    This $1.5 billion hack is exposing just how ‘irreversible’ stolen crypto really is

    August 8, 2026

    Does this video show SpaceX rocket crashing into the moon?

    August 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.