news.mlab.sh
Back to the feed
vulnerability

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

Critical
Summary

A critical one-click vulnerability, dubbed RovoBlast, has been discovered in Atlassian’s Rovo AI assistant, allowing attackers to inject malicious prompts and exfiltrate sensitive data from various Atlassian products and integrated services, including Jira, Confluence, Bitbucket, Slack, Google Workspace, and Microsoft 365. The vulnerability was patched by Atlassian before public disclosure, but Varonis Threat Labs recommends that organizations limit Rovo’s access, disconnect unused integrations, and closely monitor assistant activity logs to mitigate the risk.

Read the full article at SecurityWeek

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.