Hidden Text in PDFs Is Hijacking This AI Assistant

Lời nói đầu:PromptArmor reports that Atlassian's Rovo AI assistant can be hijacked through hidden instructions embedded in uploaded files such as PDFs, enabling data exfiltration to attacker-controlled URLs without any human approval. The attack works even when organizations disable Rovo's web search, because the tool for opening search results remains active. PromptArmor disclosed the issue to Atlassian on May 23, but after more than two months of silence from the company, Rovo remains vulnerable. This indirect prompt injection exploits AI agents' inability to distinguish user commands from planted text, directing Rovo to gather sensitive data and send it to a malicious destination.

In brief

  • Security company PromptArmor says the Rovo AI assistant can be steered to exfiltrate data with no human approval, via hidden instructions in an uploaded file, like PDFs.
  • The trick works even when an org disables Rovo's web search, because the URL-opening tool stays live.
  • Atlassian, the maker of Rovo, got the report on May 23 and went quiet; two months on, Rovo “remains vulnerable,” the security firm says.

Remember when black-hat SEOs stuffed web pages with white-on-white keywords—invisible to readers, readable to Google—to game the search rankings? Hackers are doing the same thing with AI models now. The attacker hides instructions inside a PDF document, the model can't tell the difference between the user's words and the planted ones, and it obeys.

Per PromptArmor's disclosure, Rovo—Atlassian's agent that reaches across Jira, Confluence, and the rest of your workspace—can be turned into a data pipeline with a single poisoned file. A victim asks Rovo to organize some tickets, uploads a document, and the document is carrying a concealed prompt (for example an instruction written in transparent color and a font at 1pixel in size).

The eye can‘t see it, but an Agent recognizes that text as another text in the document. That prompt tells Rovo to gather sensitive data and paste it onto an attacker-controlled URL. The firm calls it a zero-click attack. There’s no approval click, and no warning.

Rovo AI assistant getting hijacked. Screenshot: PromptArmor

A prompt injection is when someone slips instructions into content an AI is reading, hijacking it from its real operator. “Indirect” just means the poison lives in a file or webpage rather than in the chat box. Rovo's job is to read things and act on them, so a hidden line that says “send the confidential tickets here” reads to the model like a legitimate command.

PromptArmor says the leak “succeeds even if an organization has disabled web search for Rovo. This is because the web search setting fails to remove the tool for opening the search results.” Turn the feature off, and the door stays open.

Rovo AI assistant getting hijacked. Screenshot: PromptArmor

Rovo isn't a hobbyist tool. It sits on top of a company's most sensitive project data, and it acts on its own. AI agents built on GPT-5 and Gemini failed to resist prompt injection more than 79% of the time in direct tests—and Rovo shows the indirect version landing in a shipping enterprise product. The pattern keeps repeating with agents that can read and act being pointed the wrong way.

Atlassian processed the report and thanked PromptArmor, the firm says, then went silent. Rovo, PromptArmor concludes, “remains vulnerable.”

Miễn trừ trách nhiệm

Các ý kiến ​​trong bài viết này chỉ thể hiện quan điểm cá nhân của tác giả và không phải lời khuyên đầu tư. Thông tin trong bài viết mang tính tham khảo và không đảm bảo tính chính xác tuyệt đối. Nền tảng không chịu trách nhiệm cho bất kỳ quyết định đầu tư nào được đưa ra dựa trên nội dung này.
Bài viết trước

Grayscale 静悄悄地放弃了 Cardano、Polkadot 和 Hedera 的 ETF 计划

Bài tiếp theo

Tại sao cổ phiếu Nvidia giảm vào thứ Hai dù có thỏa thuận AI trị giá 500 tỷ USD trên Phố Wall?