csoonline.com

Rovo One-Click Flaw Lets Prompt Injection Potentially Expose Enterprise Data

Atlassian logoAtlassian
Sig4.25Sen-6.60Env0.00Soc-5.20Gov-6.25

Atlassian’s enterprise AI assistant Rovo, connected to tools like Slack, Microsoft 365, and Google Workspace, was found vulnerable to prompt-injection data leaks. A single click on a crafted link can trigger embedded instructions that make Rovo trust externally supplied parameters, potentially allowing access to anything it can access. Rovo connects to 50+ platforms and can’t be fully uninstalled, with built-in automation that could accelerate exfiltration. Atlassian did not immediately comment.

Coverage (1)

ABOUT

What is Fimmer?

Most feeds treat all company headlines the same. An executive interview, an office closure, stock analysis, and a data breach can sit side by side with no sense of scale. Fimmer ranks coverage by what matters, so important events stand out and signals are prioritised over noise. We cluster related company news and score each story using a range of metrics, so you see the most crucial stories first.

SCORING

What do the scores mean?

Significance (0–10) measures the scale of the real-world impact. Sentiment and ESG (−10 to +10) indicate the tone of the coverage and whether the change relates to environmental, social, or governance factors. Together, these scores help distinguish meaningful developments from routine company news. More information about our scoring methodology can be found on our About page.

DISCOVERY

Explore more on Fimmer

Search more than 10,000 public companies, browse the company index, explore their scores, and read the coverage behind them, with our core features available to everyone for free.

For more advanced features, Pro gives you access to dynamic feeds, custom sorting, and more ways to track the companies that matter to you.

More with Pro