Top AI Product

Every day, hundreds of new AI tools launch across Product Hunt, Hacker News, and GitHub. We dig through the noise so you don't have to — surfacing only the ones worth your attention with honest, no-fluff reviews. Explore our latest picks, deep dives, and curated collections to find your next favorite AI tool.


Atlassian Rovo leaks Jira data through prompt injection — PromptArmor reported it May 23, still unfixed

Rovo is Atlassian’s AI agent baked into Jira and Confluence. Security firm PromptArmor just showed it can be turned into a data exfiltration tool, and the disclosure hit 269 points on HackerNews.

How the attack works

An attacker hides instructions inside an uploaded file. A user asks Rovo to summarize Jira tickets — normal request. The agent reads the poisoned file, obeys the hidden instructions, packs sensitive ticket and Confluence data into a URL, and sends it to the attacker’s server. Zero clicks, no approval prompt, almost nothing in the chat logs.

The nastier part: disabling web search org-wide doesn’t help. Rovo’s URL retrieval tool stays active, so the exfiltration channel stays open. The control admins think protects them doesn’t.

74 days, one case number

PromptArmor reported this on May 23. As of the August 5 disclosure, Atlassian had responded with a case number and nothing else. For an agent with read access to a company’s entire Jira and Confluence, that’s the real story — enterprise AI agents are shipping faster than anyone is securing them.


You Might Also Like


Discover more from Top AI Product

Subscribe to get the latest posts sent to your email.



Leave a comment