4 min read
Vulnerabilities Varonis disclosed at DEF CON 34 that Atlassian Rovo's URL parameter pre-fills the AI agent with attacker-controlled prompts, enabling a one-click attack that directs Rovo's ResearchAgent to exfiltrate Jira, Confluence, Slack, and M365 data to an attacker URL.