ZeroHour

Search: “rovo”

5 stories

Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant

Atlassian fixed RovoBlast, a flaw letting a single crafted link make its Rovo AI assistant exfiltrate company data.

Researchers disclosed a vulnerability dubbed RovoBlast affecting Atlassian's Rovo AI assistant. A single crafted link could cause the assistant to exfiltrate company data accessible to it. Atlassian has since fixed the flaw; no widespread exploitation was reported in the disclosure.

Infosecurity Magazine · Aug 10, 2026Vulnerability

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

Varonis discloses CoSnitch (CVE-2026-24301), three Microsoft Copilot Personal flaws enabling one-click exfiltration of connected-app data; patched August 18, 2026.

Varonis Threat Labs found that an undocumented autorun=1 parameter, paired with the q parameter, lets an attacker-supplied prompt run automatically on page load in a victim's authenticated Copilot session, then exfiltrate data from connected services such as mail, calendar, Google Drive, chat history and the memory store via Copilot's built-in URL fetch to an attacker webhook. A separate memory-poisoning path through web summarization lets a crafted page persist attacker instructions in the user's memory, surviving password changes, session revocation and device re-enrollment. Microsoft shipped patches on August 18, 2026, tracked as CVE-2026-24301, and Varonis found no evidence of in-the-wild exploitation. The flaws were found via 'meta-hacking', asking Copilot itself to reveal the autorun parameter and its protections.