Fetching from the wire…
Public story · 2026-08-06 · high
Atlassian's Rovo assistant still exfiltrates Jira and Confluence data 2.5 months after disclosure, the backdrop the new containment tools shipped against.
Why now: Zed's v1.14, Cloudflare OS's Gatekeeper services, and Mistral's Shieldstral all shipped within 48 hours of PromptArmor's August 5 disclosure that Atlassian's Rovo remains exploitable, turning three separate product releases into one signal.
Zed, Cloudflare, and Mistral shipped enforced agent containment within 48 hours of each other, per all three vendors.
None of the three trust an agent's own instructions to hold under attack, a bet the industry has been making by default. Security teams evaluating agent tools now have three live examples of containment enforced outside the model, not promised inside it.
Zed's v1.14 turns on OS-level sandboxing for its agent's terminal and fetch tools by default.
Cloudflare OS added Gatekeeper services that mediate an agent's external network access and log what data it actually touches.
Mistral released Shieldstral, an open-weights model that runs outside the agent and classifies its actions against policy at runtime.
PromptArmor disclosed on August 5 that Atlassian's Rovo assistant can still be tricked into exfiltrating Jira and Confluence data with zero clicks. That's 2.5 months after Atlassian was first told. PromptArmor's disclosure doesn't say whether a fix is coming.
An agent can't be restricted by telling it not to do something. The restriction has to live somewhere the agent can't touch: the OS, the network gateway, or a second model watching the first.
Related coverage counted more than 15 vendors launching agent-infrastructure security products at Black Hat USA 2026.
A separate report found open-weights tools undercutting paid tiers in four unrelated categories, a pattern Mistral's open release fits.
The bet worth making: Rovo stays exploitable until enterprise customers, not Atlassian, force a fix. Selling agent safety as a system prompt increasingly reads as a promise instead of a control. Watch whether the next wave of agent tools ships containment as a default, the way Zed did, or bolts it on after a review.
Each link below shares sources, entities, or timing with this story.
Same source
Cite the same source (Multiple Sources (PromptArmor, Zed, Cloudflare, Mistral AI)).
Semantically similar
Covers closely related ground (similarity 0.77).
Same source domain
Reported by the same outlet (promptarmor.com).
Reported by the same outlet (promptarmor.com).
Semantically similar
Covers closely related ground (similarity 0.75).
Covers closely related ground (similarity 0.74).
Covers closely related ground (similarity 0.73).
Covers closely related ground (similarity 0.73).