Atlassian RovoBlast flaw risks data exfiltration
🛡️ Varonis disclosed a vulnerability called RovoBlast in Atlassian's enterprise AI assistant, Rovo, which allowed a crafted URL parameter to seed attacker instructions into an authenticated session. The assistant's ResearchAgent could then browse the web and post retrieved internal data externally, enabling data leakage with a single click. Atlassian has since patched the issue; Varonis urges restricting connectors, disabling browsing agents, and monitoring agent activity.
