mimile
Back to feed
This event is part of a larger story
Франция, Казахстан, Польша: кибератаки раскрыли данные сотен тысяч
Read briefing

Varonis demonstrates one-click flaw in Atlassian Rovo exposing enterprise data

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Varonis demonstrates one-click flaw in Atlassian Rovo exposing enterprise data

Varonis researchers demonstrate a one-click prompt injection attack on Atlassian's Rovo AI assistant at DEF CON 34 that exposes enterprise data across connected platforms. The attack allows an attacker to access sensitive information by crafting a link that injects malicious instructions into a user's Rovo session. Atlassian has since patched the vulnerability.

The RovoBlast Attack

Varonis researcher Dolev Taler detailed the attack at DEF CON 34, which exploits a parameter in Rovo Chat's URL scheme. A single click on a crafted link injects attacker-controlled instructions into the user's Rovo session. The attack, dubbed RovoBlast, does not require jailbreaks or complex prompt engineering. Rovo, integrated with over 50 platforms including Slack, Microsoft 365, and Google Workspace, then treats the injected instructions as trusted inputs.

Data Exfiltration Risk

The vulnerability allowed attackers to enumerate and search data across all sources accessible to Rovo, potentially including Jira, Confluence, Bitbucket, databases, and uploaded files. Varonis found that Rovo's ResearchAgent could perform autonomous multi-step web research, enabling a chain where internal data is moved to an external destination. Since Rovo's actions appear legitimate, the data theft could go unnoticed. Taler noted that Rovo cannot be fully uninstalled, leaving organizations with persistent attack surface.

What's Next

Atlassian has patched the vulnerability, but Varonis warns that robust input validation and security controls remain critical. It is unclear whether similar prompt injection flaws exist in other enterprise AI assistants with broad data access.

1 source

Varonis demonstrates one-click flaw in Atlassian Rovo exposing enterprise data