NewsLayer.com
NewsLayer PulseLIVEBTC$84,437+0.35%ETH$2,691-0.07%SOL$121.71-0.12%XRP$1.51-2.44%DOGE$0.0968-1.84%ADA$0.2538-2.50%Total Cap$2.85T-0.28%Layer Index56 Neutral

Hidden Text in PDFs Is Hijacking This AI Assistant

A security firm says Atlassian's AI assistant will quietly ship your Jira tickets and Confluence docs to an attacker, using instructions buried in a file you'd swear was empty.

Jose Antonio Lanz

Publisher Decrypt

Aug 10, 2026 at 7:56 PM UTC · 2 분 소요

Hidden Text in PDFs Is Hijacking This AI Assistant
Image via Decrypt
번역 중…

In brief

  • Security company PromptArmor says the Rovo AI assistant can be steered to exfiltrate data with no human approval, via hidden instructions in an uploaded file, like PDFs.
  • The trick works even when an org disables Rovo's web search, because the URL-opening tool stays live.
  • Atlassian, the maker of Rovo, got the report on May 23 and went quiet; two months on, Rovo "remains vulnerable," the security firm says.

Remember when black-hat SEOs stuffed web pages with white-on-white keywords—invisible to readers, readable to Google—to game the search rankings? Hackers are doing the same thing with AI models now. The attacker hides instructions inside a PDF document, the model can't tell the difference between the user's words and the planted ones, and it obeys.

Per PromptArmor's disclosure, Rovo—Atlassian's agent that reaches across Jira, Confluence, and the rest of your workspace—can be turned into a data pipeline with a single poisoned file. A victim asks Rovo to organize some tickets, uploads a document, and the document is carrying a concealed prompt (for example an instruction written in transparent color and a font at 1pixel in size).

The eye can’t see it, but an Agent recognizes that text as another text in the document. That prompt tells Rovo to gather sensitive data and paste it onto an attacker-controlled URL. The firm calls it a zero-click attack. There’s no approval click, and no warning.