ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Cybersecurity

Prompted Rovo actions can exfiltrate Jira and Confluence data to attackers

Source headline: Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Threat level High
Signal strength 78/100
Source confidence 1 source
Published 2 hours ago

Intelligence Summary

Atlassian’s Rovo assistant can be manipulated to collect Jira or Confluence content from a signed-in user. The retrieved information can then be sent to an attacker-controlled external server. Two separate security firms observed the behavior using different prompt or instruction routes. One exploitation path has been confirmed as closed, but the full fix status is still uncertain. Users should limit sensitive content exposure in connected Atlassian spaces and monitor for unusual data access and outbound activity.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#data-exfiltration #prompt-injection #atlassian #confluence #jira #rovo
Original reporting The Hacker News Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Open original source