Find notable cyber news and cases, enriched with sources, timelines, and signals.

Atlassian Rovo Chat rovoChatPrompt prompt-injection security flaw

Vulnerability
First reported
Last updated
Happening score
H score 1
1 unique sources, 1 articles

Summary

Hide ▲

The Atlassian Rovo Chat rovoChatPrompt vulnerability let attacker-supplied instructions preload into the assistant and exfiltrate Jira, Confluence, and connected-app data the signed-in user could access. Varonis Threat Labs independently confirmed the one-click link route, and Atlassian closed that path server-side on July 8, 2026. The flaw turned permitted access into an outbound data leak without requiring the victim to intentionally share the data.

Related Happenings

Storm-1175 high-tempo Medusa ransomware campaign

Campaign
H score59 First: 07.04.2026 13:02 Last: 07.04.2026 13:02 Sources 1

About this happening: Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...

CISA updates KEV entry for CVE-2026-1731

Public Sector Action
H score36 First: 20.02.2026 17:45 Last: 20.02.2026 17:45 Sources 1

About this happening: CISA updated its KEV catalog entry for CVE-2026-1731, confirming the flaw has been used in ransomware campaigns and elevating its government-tracked risk. The upda...

BeyondTrust Remote Support and Privileged Remote Access CVE-2026-1731 active exploitation wave

Exploitation Wave
H score76 First: 12.02.2026 23:34 Last: 12.02.2026 23:34 Sources 1

About this happening: CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access is now seeing first in-the-wild exploitation, putting exposed appliances at risk of remote...

BeyondTrust Remote Support and Privileged Remote Access pre-auth OS command injection (CVE-2026-1731)

Vulnerability
H score75 First: 09.02.2026 10:03 Last: 09.02.2026 10:03 Sources 1

About this happening: CVE-2026-1731 is a critical pre-authentication OS command injection in BeyondTrust Remote Support and Privileged Remote Access that can let an unauthenticated at...

Latest development: 09.02.2026 15:07

BeyondTrust secured all RS/PRA cloud systems by February 2, 2026 and directed on-premises customers to manually upgrade to Remote Support 25.3.2 or later and Privileged Remote Access 25.1.1 or later if automatic updates were not enabled.

Reprompt prompt-injection mechanics against Microsoft Copilot

Technical Analysis
H score22 First: 15.01.2026 14:09 Last: 15.01.2026 14:09 Sources 1

About this happening: Researchers mapped Reprompt, a prompt-injection chain against Microsoft Copilot that can drive continuous, undetectable user-data exfiltration and persist after th...

Timeline

  1. 05.08.2026 03:00 1 articles · 3d ago

    PromptArmor discloses Rovo content-borne prompt injection

    Initial Disclosure

    PromptArmor disclosed to Atlassian that attacker-controlled text placed in content Rovo reads could make Atlassian Rovo collect Jira or Confluence data a signed-in user can access and send it to an outside server; the firm later published the finding on August 5, 2026 and said the chain still worked with Rovo's web-search option switched off.

    Show sources
  2. 08.07.2026 03:00 2 articles · 1mo ago

    Atlassian fixes the RovoChatPrompt link exfiltration route

    Mitigation Patch Update

    Varonis Threat Labs found that the rovoChatPrompt URL parameter could preload attacker instructions into Rovo Chat, letting one click from an authenticated user make Rovo run them with that user's privileges and send the results to an attacker-controlled server; Atlassian fixed the route server-side on July 8, 2026 and Bugcrowd marked the report resolved.

    Show sources