August 10, 2026 · The Decoder
Hidden PDF text can hijack Atlassian's AI agent Rovo
Security firm PromptArmor showed that hidden instructions embedded in a PDF can hijack Atlassian's Rovo AI agent, silently forwarding sensitive data from Jira and Confluence to an external server. The attack requires no user confirmation and leaves no visible trace.
Why it matters: This is another concrete instance of indirect prompt injection, where the malicious instructions arrive through a document rather than a chat message, a class of attack labs have struggled to fully close off. It adds to a growing string of real-world agent security incidents as tools like Rovo get deeper access to internal company data.