عاجل
TRTBMM'de Tarihi Oylama: 50 Yıllık Terör Belası Tarihe GömüldüTRUkrayna'nın Tataristan'daki Fabrika ve Rafineriye Düzenelediği Dron Saldırısında 13 Kişi ÖldüTRKolombiya'da 7.4 büyüklüğünde deprem: En az 132 ölüTRDolphin Tayfunu: Pekin'de Yağışlar Hayatı Etkilemeye Devam EdiyorTRİran, İsrail'e Ait İHA'yı Elektronik Harp İle İndirdiği İddia EdiliyorTROrganize Sanayi Bölgesi'ndeki Tekstil Fabrikasında Büyük YangınTRApple, Çinli CXMT ile bellek çipi görüşmeleri yürütüyorTRFenerbahçe otobüsüne silahlı saldırı soruşturmasında yeni gelişmelerTRVize ve Maliye Denetimleri: Kar Amacı Güden Yapılanmalar ve Karaborsa Vize İddialarıTRMenderes Belediye Başkanı İlkay Çiçek tutuklandı ve görevden uzaklaştırıldıTRTBMM'de Tarihi Oylama: 50 Yıllık Terör Belası Tarihe GömüldüTRUkrayna'nın Tataristan'daki Fabrika ve Rafineriye Düzenelediği Dron Saldırısında 13 Kişi ÖldüTRKolombiya'da 7.4 büyüklüğünde deprem: En az 132 ölüTRDolphin Tayfunu: Pekin'de Yağışlar Hayatı Etkilemeye Devam EdiyorTRİran, İsrail'e Ait İHA'yı Elektronik Harp İle İndirdiği İddia EdiliyorTROrganize Sanayi Bölgesi'ndeki Tekstil Fabrikasında Büyük YangınTRApple, Çinli CXMT ile bellek çipi görüşmeleri yürütüyorTRFenerbahçe otobüsüne silahlı saldırı soruşturmasında yeni gelişmelerTRVize ve Maliye Denetimleri: Kar Amacı Güden Yapılanmalar ve Karaborsa Vize İddialarıTRMenderes Belediye Başkanı İlkay Çiçek tutuklandı ve görevden uzaklaştırıldı
Newsgather
رجوعAtlassian's Rovo AI Vulnerable to Indirect Prompt Injection via Hidden Text
Atlassian's Rovo AI Vulnerable to Indirect Prompt Injection via Hidden Text
يتطور
Decryptقبل 10 ساعاتتقنية1 د قراءة

Atlassian's Rovo AI Vulnerable to Indirect Prompt Injection via Hidden Text

Security firm PromptArmor reveals Atlassian's Rovo AI agent can be exploited using hidden text in documents to exfiltrate sensitive enterprise data.

نظرة سريعة

Security firm PromptArmor discovered that Atlassian's Rovo AI agent is vulnerable to indirect prompt injection via invisible text in uploaded documents, allowing data exfiltration without user approval.

ملخص مُنشأ بالذكاء الاصطناعي

لماذا يهم

PromptArmor disclosed a zero-click vulnerability in Atlassian's Rovo AI agent allowing indirect prompt injection via hidden text.

حجم الخط

Remember when black-hat SEOs stuffed web pages with white-on-white keywords—invisible to readers, readable to Google—to game the search rankings? Hackers are doing the same thing with AI models now. The attacker hides instructions inside a PDF document, the model can't tell the difference between the user's words and the planted ones, and it obeys.

Per PromptArmor's disclosure, Rovo—Atlassian's agent that reaches across Jira, Confluence, and the rest of your workspace—can be turned into a data pipeline with a single poisoned file. A victim asks Rovo to organize some tickets, uploads a document, and the document is carrying a concealed prompt (for example an instruction written in transparent color and a font at 1pixel in size).

The eye can’t see it, but an Agent recognizes that text as another text in the document. That prompt tells Rovo to gather sensitive data and paste it onto an attacker-controlled URL. The firm calls it a zero-click attack. There’s no approval click, and no warning.

A prompt injection is when someone slips instructions into content an AI is reading, hijacking it from its real operator. "Indirect" just means the poison lives in a file or webpage rather than in the chat box. Rovo's job is to read things and act on them, so a hidden line that says "send the confidential tickets here" reads to the model like a legitimate command.

PromptArmor says the leak "succeeds even if an organization has disabled web search for Rovo. This is because the web search setting fails to remove the tool for opening the search results." Turn the feature off, and the door stays open.

Rovo isn't a hobbyist tool. It sits on top of a company's most sensitive project data, and it acts on its own. AI agents built on GPT-5 and Gemini failed to resist prompt injection more than 79% of the time in direct tests—and Rovo shows the indirect version landing in a shipping enterprise product. The pattern keeps repeating with agents that can read and act being pointed the wrong way.

Atlassian processed the report and thanked PromptArmor, the firm says, then went silent. Rovo, PromptArmor concludes, "remains vulnerable."

"Atlassian assigned a case number and expressed thanks, but after multiple follow-ups by PromptArmor over more than two months, Atlassian has made no further communication, and Rovo remains vulnerable," the firm wrote.

ما الذي يجب مراقبته

توقعات الذكاء الاصطناعي — احتمالات وليست حقائق

  • Atlassian will address the reported Rovo vulnerability after public disclosure.

    مرجح · خلال أسابيع

أسئلة مفتوحة

  • Will Atlassian issue a patch for Rovo?
  • Are other enterprise AI agents affected similarly?

مواضيع ذات صلة

This article was originally published by Decrypt.

أخبار ذات صلة

المزيد حول هذا الموضوعprompt injection