Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Latest AI and industry news. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

News AI News

Atlassian Rovo's zero-click prompt-injection exfiltration flaw (see Under the Radar),

Atlassian Rovo's zero-click prompt-injection exfiltration flaw (see Under the Radar), worth flagging twice since it's both a security story and a live.

Enterprise DNA |
Atlassian Rovo's zero-click prompt-injection exfiltration flaw (see Under the Radar),

AI Pulse · AI Trends Pulse

Atlassian disclosed a vulnerability in Rovo, its AI assistant for Confluence and Jira, that let attackers steal data without anyone clicking anything. The flaw involved prompt injection, a technique where malicious instructions hidden in documents trick the AI into following new orders. In this case, an attacker could embed a prompt in a Confluence page, and when Rovo indexed that page, the hidden instruction would fire automatically. The AI could then exfiltrate sensitive information to an external server, all without the user or admin knowing.

Atlassian patched the issue, but the episode is worth noting for two reasons. First, it is a clean example of how AI agents that read and act on your internal documents introduce a new attack surface. Traditional software does not interpret text as executable logic. AI does. That changes the threat model. Second, this is not theoretical. Rovo is a production tool used by real companies, and the vulnerability was present in the wild.

What this means for governance

If you are running or evaluating AI tools that connect to your company’s data, you need to ask how they handle untrusted input. Can someone slip a prompt into a shared document, a support ticket, or a CRM note that the AI will treat as an instruction? Do you have logging that shows what the AI reads and what it sends out? These are not edge cases anymore. They are baseline questions for any AI deployment that touches internal systems. The kind of monitoring and access controls that catch this sort of thing early are exactly what we build into an AI command centre, where you can see what your agents are doing and set boundaries before something leaks.

Atlassian moved quickly, but the lesson is broader. AI tools that act on your behalf need the same scrutiny you would give any system with write access to your data.

Free daily email

Get this every morning.

This brief is one item from today's AI Pulse, the short daily read we run for ourselves on what is actually happening in AI. Subscribe free and it lands in your inbox each morning.

Free daily email

Subscribe to the daily AI Pulse

One short read every morning on what is actually happening in AI. Free.

One email a day. Unsubscribe any time.