AI Assistants: A New Door for Data Theft
According to a recent report from The Hacker News, security researchers found that Atlassian's Rovo AI assistant could be exploited to send sensitive business data from Jira and Confluence to attackers. The attacks worked by hiding instructions inside files or links that the assistant then followed, leaking information without the user realising it. This is not just a one-off bug – it points to a much bigger problem with how AI tools handle the content they read.
The key issue is something called prompt injection. In simple terms, an attacker plants commands inside a document or a link that the AI treats as legitimate instructions. When a user asks Rovo to do something normal – like organise tickets – the assistant also follows the hidden orders and sends data to an outside server. One of the two reported flaws has been fixed by Atlassian, but the other remains unpatched. That means businesses cannot simply assume their AI tools are safe just because they have updated their software.
Why This Matters Beyond Atlassian
These findings show that AI assistants connected to internal company systems create a new type of risk. The assistant has access to everything the user can see, and it can be tricked into sending that data out. Even turning off features like web search does not stop all data leaks, because the assistant can still fetch URLs on its own. This is a reminder that security settings designed for humans may not work the same way for AI agents.
For Australian businesses, this is especially important because many rely on Atlassian products for project management and collaboration. A single employee clicking a malicious link or uploading an infected file could expose client records, financial details, or strategic plans. The attacks described do not require the attacker to break into the system – they simply abuse the permissions that the user already has. That makes these threats harder to detect with traditional security tools.
What This Means for Australian SMBs
Small and mid-sized businesses in Australia often have fewer resources for cybersecurity. They may have turned on Rovo without understanding the potential for data exfiltration through AI prompts. If your team uses Jira or Confluence, the risk is real: an attacker could send a seemingly harmless file or link, and Rovo could do the rest. The data stolen might include customer information, intellectual property, or internal communications – all of which can damage trust and lead to legal problems.
The good news is that you are not helpless. The flaws rely on the assistant having broad access and on users interacting with untrusted content. By controlling who can use Rovo and what data it can reach, you can limit the damage even if a prompt injection occurs. Australian SMBs should treat AI assistants like any other powerful tool – lock them down until you understand how they behave.
What You Can Do Now
- Review your Atlassian admin settings. Disable Rovo for apps that do not need AI features, or restrict it to specific user groups using Enterprise access controls.
- Educate your team about the risk of opening files or clicking links from unknown sources. Explain that AI assistants can be tricked even by documents that look safe.
- Monitor outbound network traffic from your Atlassian instances. Look for unexpected connections to unfamiliar servers, especially from users who have access to sensitive data.
- Consider temporarily turning off Rovo Chat and Agents for the most sensitive projects until Atlassian confirms all prompt injection paths are closed.
- Work with a cybersecurity partner to assess your AI tool configurations and run simulated attacks to see if data could leak.
Australian SMBs do not have to face these challenges alone. MS&VG helps businesses like yours understand the real risks of AI tools and put practical controls in place – so you can use technology without exposing your data.