Hidden text in a PDF is enough to steal sensitive data through Atlassian's AI agent Rovo
Security researchers found a way to exploit Atlassian's Rovo AI agent using hidden PDF text, enabling silent data theft from Jira and Confluence without user interaction.

- Hidden text in PDFs can hijack Atlassian's Rovo AI agent to silently exfiltrate data from Jira and Confluence.
- The attack requires no user interaction and leaves no trace, making it highly stealthy.
- This exploit underscores the emerging risks of AI agent vulnerabilities in enterprise software.
- Organizations using Atlassian's tools should monitor for updates addressing this security flaw.
Security firm PromptArmor uncovered a critical vulnerability in Atlassian's Rovo AI agent that allows attackers to exfiltrate sensitive data from Jira and Confluence through malicious PDFs. The attack leverages hidden text within PDF files to inject instructions that Rovo executes automatically, forwarding data to an external server without requiring user confirmation or leaving detectable traces. This exploit bypasses standard security measures by abusing the AI agent's document processing capabilities, posing a significant risk to organizations relying on Atlassian's ecosystem for sensitive workflows.
The vulnerability highlights the growing threat of AI-specific attack vectors, where AI agents with access to critical systems can be manipulated through seemingly innocuous inputs like documents. Unlike traditional phishing or malware attacks, this method requires no user interaction beyond the initial document upload, making it stealthier and harder to detect. Atlassian has not yet publicly addressed the issue, raising concerns about the broader security implications for AI-powered productivity tools.
AI agents like Rovo must implement strict input validation to prevent malicious instruction injection.
Companies using Atlassian's AI tools face a new class of stealthy data exfiltration risks.
Security vulnerabilities in AI agents could impact the valuation of companies relying on such tools.
AI-powered productivity tools may introduce unforeseen security risks that require immediate attention.
- Rovo
- Atlassian's AI agent designed to assist with tasks in Jira and Confluence.
- Exfiltration
- The unauthorized transfer of data from a system.
As AI-led attacks multiply, OpenAI launches a new cyber model
Newsom to California agencies: Better prepare for artificial intelligence attacks - Sacramento Bee
SecurityOpenAI launches GPT-5.6-Cyber to help defenders find vulnerabilities before attackers do
Governor Newsom announces new AI cyber defense program to protect California’s critical infrastructure - gov.ca.gov
SecurityA researcher bought noreply.net. Companies started sending him secrets.
North Carolina Central University made history as the first HBCU in the nation to launch a dedicated AI research center - ABC11 News
North Carolina Central University opened the first AI research center at an HBCU, marking a historic milestone for historically Black institutions.
Five takeaways from Zuckerberg’s AI manifesto - The Detroit News
Meta CEO Mark Zuckerberg outlines five core principles for AI development in a new manifesto, emphasizing open-source collaboration and ethical deployment.
BusinessWith new open models, Meta pitches another reboot of its struggling AI strategy
Meta unveils new open-source AI models to regain ground against rivals, signaling a strategic pivot after falling behind in the AI race.
NCCU opens nation’s first HBCU artificial intelligence insti... - QCity Metro
North Carolina Central University has opened the first artificial intelligence institute at an HBCU, aiming to advance AI education and research for underrepresented groups.
Artificial intelligence institute opens at N.C. Central University - WPTF
North Carolina Central University has opened a dedicated artificial intelligence institute to advance research and education in AI technologies.
BusinessAmazon backs power plant that may become top source of US climate pollution
Amazon is funding a large natural gas power plant to support its first off-the-grid data center dedicated to AI workloads.