Agents
RovoBlast: one link seeds attacker instructions into an Atlassian Rovo session and its ResearchAgent exfiltrates the data
Varonis Threat Labs disclosed at DEF CON 34 that Rovo's `rovoChatPrompt` URL parameter pre-fills content straight into a victim's live AI session, and leaving the organization ID blank silently routes the request into the victim's own default org with no warning. Rovo's built-in ResearchAgent — which can autonomously browse multiple sources and navigate arbitrary sites — then pulls internal Jira, Confluence and SharePoint content and pushes it to the open web in a single automated chain. Varonis calls the class parameter-to-prompt (P2P) injection, the same pattern they reported in Microsoft Copilot as Reprompt in January; Atlassian fixed it before publication.
Source
↳ Follow the thread