PDF Hijacks Atlassian's Rovo AI Agent With No Trace Left
A line of hidden white text inside an ordinary PDF is all it takes to make Atlassian's Rovo AI agent silently exfiltrate corporate data — no user confirmation, no chat logs. No patch has shipped in 2.5 months.
A line of white text on a white background inside an ordinary PDF — and Atlassian's Rovo AI agent silently exfiltrates corporate data: Jira tickets, Confluence documents, architecture specs — straight to an attacker's server. Security firm PromptArmor discovered the attack: no user confirmation, no trace in the chat — the agent simply executes the hidden command. Atlassian was notified on May 23 and has not shipped a patch in 2.5 months.
AI agents with access to enterprise systems are becoming a new threat class: the more autonomous the agent, the easier it is to hijack. Prompt injection — embedding hidden instructions via documents — has become a standard attack vector against enterprise AI, and the window between discovery and remediation is stretching into months.
Source: the-decoder.com
Free course
Stop reading about AI — start building with it
The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.
Start free →▌ Related guides

Author
Evgenii Arsentev
PhD · Chief Executive Officer, digital health
Articles · Latest articles