Back Issues This Week → Calendar → Current Issue → Popular →

All issuesVolume 341, Issue 1IT Vendor NewsVaronis

RovoBlast: How One Click Triggered Atlassian's AI Assistant to Leak Data

Varonis, Friday, August 7th, 2026

Varonis Threat Labs discloses RovoBlast, a one-click prompt injection against Atlassian's Rovo AI assistant.

Varonis Threat Labs has uncovered a vulnerability in Rovo, Atlassian's enterprise AI assistant.

Dubbed RovoBlast, the attack requires only a single click on a link from the victim. That click triggers the attacker's embedded instructions, forcing Rovo to accept externally supplied parameters as trusted inputs within the user's session.

Because the assistant operates with the user's own access, the technique can be used to extract data the user can reach.

more →  ·  More from Varonis →