Hidden PDF text can hijack Atlassian's Rovo agent

Share
Hidden PDF text can hijack Atlassian's Rovo agent

Two threads define the last few hours: a security firm shows that a rigged PDF is all it takes to make an enterprise AI agent hand over internal documents, and fresh OpenRouter data confirms Chinese models have now led global API call volume for a quarter of a year straight.

A hidden prompt injection in an innocent-looking PDF can make Atlassian's Rovo agent silently ship Jira tickets and Confluence documents to an attacker's server. Security firm PromptArmor documented the indirect prompt-injection attack, which needs no user confirmation and leaves no trace in the chat window. A user asks Rovo to, say, organize their tickets and uploads a PDF; hidden white-on-white one-point text hijacks the agent when it processes the request. Rovo then gathers matching Jira and Confluence content, stuffs it into a dynamically built URL, and fetches it with its URL-retrieval tool — dumping complete tickets, assignments, priorities, and internal docs like onboarding guides and platform architecture notes onto the attacker's infrastructure. Disabling web search doesn't stop it: that setting kills search but not the URL-reading tool. PromptArmor says it reported the flaw on May 23 and got a case number two days later, but Atlassian never responded to follow-ups on June 4 and July 29, and the agent was still vulnerable as of the firm's August 5 disclosure. It's the same class of bug that keeps surfacing across agentic products — Microsoft Copilot's Word-document worm was reported just weeks ago — and it's a reminder that giving agents broad read access to internal systems is exactly what makes them a channel for exfiltration.


Chinese large models have now outpaced US models in weekly API call volume for 15 consecutive weeks, according to fresh OpenRouter data. In the week of August 3–9, Chinese models accounted for 34.25 trillion tokens — roughly 3.7 times the 9.17 trillion from US models — though US volume grew faster week-over-week (109% vs 21.8%). The standout: DeepSeek's V4-Flash general release (0731), which launched in public beta on July 31 and shot straight to the top of the global chart with 8.83 trillion tokens, up 570% week-over-week. Tencent's Hy3, DeepSeek's V4-Flash preview, and Xiaomi's MiMo-V2.5 rounded out the top four, all Chinese; OpenAI's GPT-5.6 Luna took fifth with 4.43 trillion tokens (+128%), and Google's Gemini 3.6 Flash debuted at ninth. The economics explain the shift: per Artificial Analysis, V4-Flash completes a task for about $0.03 on average — roughly one-hundredth the cost of Anthropic's Claude Fable 5 — making it the cheapest mainstream model in the world. China's lead is increasingly a price-performance story, and the US response so far is a price war of its own (OpenAI cut GPT-5.6 Luna pricing 80% last month).

What to watch: Whether Atlassian ships a fix for the Rovo flaw — and whether enterprise buyers start treating every uploaded file as untrusted input.

If your team runs an AI agent with access to internal docs, how do you decide what it's allowed to read? Tell us in the comments.

Sources: PromptArmor · The Decoder · SecurityWeek · The Hacker News · 每日经济新闻 via 证券时报 · 财联社 · 观点网 · OpenRouter