Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Latest AI and industry news. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

News AI News

PromptArmor disclosed a zero-click data exfiltration flaw in Atlassian Rovo: indirect

PromptArmor disclosed a zero-click data exfiltration flaw in Atlassian Rovo: indirect prompt injection let an attacker pull Jira/Confluence data with.

Enterprise DNA |
PromptArmor disclosed a zero-click data exfiltration flaw in Atlassian Rovo: indirect

AI Pulse · Under the Radar

A security firm called PromptArmor found a hole in Atlassian Rovo, the AI assistant that searches across your Jira tickets and Confluence pages. The flaw let an attacker pull internal company data without anyone clicking anything or giving permission. It worked through indirect prompt injection, which means the attacker hid malicious instructions in content the AI read, then the AI followed those instructions and leaked data to an external server.

The attack bypassed Atlassian’s organization-level controls that are supposed to stop the AI from searching the web. An attacker could plant a trigger in a public document, wait for Rovo to index it, and watch company information flow out. The disclosure has been live on Hacker News for a day with modest discussion but no major tech press coverage yet. Atlassian patched a related one-click version of the vulnerability, but the full status of the zero-click path is not clear from what PromptArmor has published.

This matters because Rovo is not some experimental toy. It sits inside production environments with access to tickets, roadmaps, customer notes, and internal wikis. If your team uses it, the AI has read everything. The indirect injection angle is harder to defend against than a phishing link because no one has to do anything wrong. The AI does the work on its own once it ingests the poisoned content.

What to check now

Ask your IT team whether Rovo is enabled and what data sources it can reach. If you run any AI agent that searches internal documents, you need to know what guardrails are actually in place and whether they hold up under this kind of attack. Tools like the Omni Command Centre let you audit which AI systems touch which data and set boundaries that do not rely on vendor promises alone. Treat AI assistants like you would any other service with broad read access. They are not passive search boxes anymore.

Free daily email

Get this every morning.

This brief is one item from today's AI Pulse, the short daily read we run for ourselves on what is actually happening in AI. Subscribe free and it lands in your inbox each morning.

Free daily email

Subscribe to the daily AI Pulse

One short read every morning on what is actually happening in AI. Free.

One email a day. Unsubscribe any time.