Opening SecureFlowRovoBlast: rovoChatPrompt One-Click Data Exfiltration
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

Varonis Threat Labs aidefend-sf0037

RovoBlast: rovoChatPrompt One-Click Data Exfiltration

  • Autonomous Agents
  • Copilot & SaaS
  • RAG & Knowledge Systems
  • Data Exfiltration

RovoBlast abused the externally supplied rovoChatPrompt URL parameter to seed instructions into an authenticated Rovo session without a warning or confirmation. ResearchAgent then searched sources available to the victim and sent selected data through an attacker-controlled URL or image request. Atlassian deployed a server-side fix on July 8, 2026.

Mapped threat techniques

  • AML.T0051.000 LLM Prompt Injection: Direct
  • AML.T0053 AI Agent Tool Invocation
  • AML.T0025 Exfiltration via Cyber Means

Source