Researchers at DEF CON 34 from Varonis demonstrated a one-click prompt injection attack against Atlassian's Rovo AI assistant via the rovoChatPrompt parameter that leaked sensitive data across connected Slack and Microsoft 365 systems. The vulnerability allowed attackers to bypass built-in safety boundaries and extract information from multiple integrated enterprise applications.
Topics #
Sources #
- Press
Go deeper #
This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.