Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Security alert graphic about AI assistants being weaponised to leak business data through prompt injection attacks

Atlassian’s AI Assistant Was Caught Leaking Jira and Confluence Data

Security researchers at Varonis and PromptArmor independently found that Atlassian’s Rovo AI assistant — the one built into Jira, Confluence, and a growing list of connected SaaS tools — can be manipulated into collecting internal business data and sending it to an attacker-controlled server.

One attack path, dubbed RovoBlast, required just a single click on a crafted link. Another worked by hiding instructions inside a document that Rovo was asked to process. Varonis’s link-based attack was fixed by Atlassian on 8 July. The document-based path was still unresolved as of 5 August.

The scope is what makes this significant. Rovo had access to Jira tickets, Confluence pages, Bitbucket, Slack, Microsoft 365, Google Workspace, and more than 50 additional connectors. Every piece of data a signed-in user could reach, Rovo could reach too — and the attack exploited that trust without triggering a single approval prompt.

Why this matters beyond Atlassian

This isn’t just an Atlassian problem. It’s a pattern we’re watching closely across Australian client environments: businesses are connecting AI assistants to sensitive internal systems without reviewing what those tools can actually access or do autonomously. The attack here didn’t exploit a traditional software bug. It exploited the fact that AI assistants treat content as instructions when they shouldn’t — a technique called prompt injection.

If your business has enabled any AI assistant with broad access to internal tools — whether it’s Rovo, Microsoft Copilot, or something else — you have the same structural risk. The AI becomes the attack surface, not just the target.

What to do now

Audit which AI assistants are active in your environment and what data they can reach. Disable AI features your team doesn’t actively use, especially autonomous browsing and agent capabilities. Restrict AI tool access to sensitive areas — HR records, financial data, client information, legal documents — by default, not as an afterthought. And review connected third-party integrations: if you’re not using a connector, remove it.

How All IT Services can help

If you’re unsure what AI tools are running across your Microsoft 365 or SaaS stack, a cybersecurity review is the fastest way to get visibility. We help businesses across Sydney, the Central West, Brisbane, and Melbourne lock this down before it becomes an incident rather than a headline.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →