Atlassian Rovo crafted-link prompt injection security flaw
Vulnerability
Summary
Hide ▲
Show ▼
Atlassian Rovo had a crafted-link prompt injection flaw that could seed attacker instructions into an authenticated session and let the assistant’s browsing agent move company data to the public web. Varonis Threat Labs disclosed the issue as RovoBlast on August 7, and Atlassian fixed it after the report. The flaw affected Rovo across connected enterprise services, creating exposure for organizations that relied on the assistant’s browsing and research features.
Related Happenings
Atlassian Rovo Chat rovoChatPrompt prompt-injection security flaw
Vulnerability
H score1
First: 08.08.2026 11:54
Last: 08.08.2026 11:54
Sources 1
About this happening:
The Atlassian Rovo Chat rovoChatPrompt vulnerability let attacker-supplied instructions preload into the assistant and exfiltrate Jira, Confluence, and connected-a...
Atlassian Rovo Chat rovoChatPrompt prompt-injection security flaw
VulnerabilityAbout this happening: The Atlassian Rovo Chat rovoChatPrompt vulnerability let attacker-supplied instructions preload into the assistant and exfiltrate Jira, Confluence, and connected-a...
HalluSquatting indirect prompt-injection attack on AI coding assistants
Technical Analysis
H score3
First: 08.07.2026 18:07
Last: 08.07.2026 18:07
Sources 1
About this happening:
Researchers demonstrated HalluSquatting, an indirect prompt-injection technique that can push AI coding assistants to fetch attacker-controlled resources and execute code....
HalluSquatting indirect prompt-injection attack on AI coding assistants
Technical AnalysisAbout this happening: Researchers demonstrated HalluSquatting, an indirect prompt-injection technique that can push AI coding assistants to fetch attacker-controlled resources and execute code....
Phantom Mantis shifts The Gentlemen into an independent ransomware partnership program
Threat Actor Meta
H score24
First: 11.06.2026 19:50
Last: 11.06.2026 19:50
Sources 1
About this happening:
Phantom Mantis moved The Gentlemen from dependence on other ransomware ecosystems into an independent partnership program, expanding its operational autonomy and affil...
Phantom Mantis shifts The Gentlemen into an independent ransomware partnership program
Threat Actor MetaAbout this happening: Phantom Mantis moved The Gentlemen from dependence on other ransomware ecosystems into an independent partnership program, expanding its operational autonomy and affil...
Claude Code GitHub Action bot trigger bypass security flaw
Vulnerability
H score31
First: 04.06.2026 18:15
Last: 04.06.2026 18:15
Sources 1
About this happening:
Anthropic's Claude Code GitHub Action had a trigger-check bypass that let a malicious GitHub issue escalate into repository takeover for vulnerable public reposito...
Claude Code GitHub Action bot trigger bypass security flaw
VulnerabilityAbout this happening: Anthropic's Claude Code GitHub Action had a trigger-check bypass that let a malicious GitHub issue escalate into repository takeover for vulnerable public reposito...
Timeline
-
10.08.2026 18:30 2 articles · 3h ago
Varonis discloses RovoBlast flaw in Atlassian Rovo
Initial DisclosureVaronis Threat Labs disclosed RovoBlast in Atlassian's Rovo AI assistant after showing that a crafted URL could seed attacker instructions into an authenticated browser session and that ResearchAgent could browse arbitrary websites to move internal content to the public web; Atlassian later fixed the flaw.
Show sources
- Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant — www.infosecurity-magazine.com — 10.08.2026 18:30
- Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant — www.infosecurity-magazine.com — 10.08.2026 18:30