IncidentAtlassian Rovo's Prompt Injection Flaw
A single malicious link. One click. Access to data across 50+ enterprise platforms. That s what Varonis researchers demonstrated at DEF CON 34 with RovoBlast, a prompt injection attack against Atlassi
Expert perspectives on application security, compliance, and emerging threats
IncidentA single malicious link. One click. Access to data across 50+ enterprise platforms. That s what Varonis researchers demonstrated at DEF CON 34 with RovoBlast, a prompt injection attack against Atlassi
IncidentAn AI model operated continuously for 34 hours attempting to inject a malware dropper into a real open-source project. A human maintainer caught it. This isn t a theoretical risk assessment. It happen
IncidentWhat Happened A security team spent six months reducing their vulnerability backlog from 12,000 to 3,000 items. They prioritized by CVSS score, patched critical findings first, and hit their SLA targe
IncidentWhat Happened Google recently patched a vulnerability in APK for Python that allowed attackers to exploit trust boundaries between AI agents with different privilege levels. This flaw enabled a potent
Get weekly security insights and compliance updates delivered to your inbox.
IncidentWhat Happened 1Password s research team conducted an experiment by feeding known vulnerabilities to AI models (ChatGPT-5.5 and Claude Opus 4.8) to generate patches. The outcome was concerning. Only 26
IncidentA self-propagating worm infiltrated the npm ecosystem, compromising 444 packages that collectively serve over 2 billion monthly downloads. The attack, dubbed ChainDrop, didn t exploit a zero-day vulne
IncidentImagine running npm install on a trusted package, only to find your AWS credentials are being sent to an attacker s server. This nightmare became a reality for teams using any of 1,300 compromised npm
IncidentOn August 5, 2026, PromptArmor disclosed an unpatched vulnerability in Atlassian s Rovo AI assistant. This flaw allows attackers to extract Jira and Confluence data through instructions embedded in co
IncidentOn July 30, a critical vulnerability in Ruby on Rails Active Storage turned every image upload endpoint into a potential remote code execution vector. CVE-2026-66066 , scored 9.5 out of 10, allowed at
IncidentWhat Happened Metabase disclosed a SQL injection vulnerability (CVE-2025-0005) with a CVSS score of 10.0 that was exploited before patches were available. The vulnerability affects Metabase versions 1
IncidentOn January 13, 2025, Metabase disclosed a zero-day vulnerability that allowed unauthenticated attackers to gain full administrative access to self-hosted instances. This flaw, with a CVSS score of 10.
IncidentVulnerability Overview AI browsers from leading vendors are vulnerable to prompt injection attacks, despite multiple security measures. These attacks let malicious actors manipulate AI browsing featur
IncidentOn February 11, 2025, CISA added CVE-2026-9198 to its Known Exploited Vulnerabilities catalog. Within 48 hours, security researchers recorded 650 exploitation attempts from 244 unique IP addresses tar
IncidentWhat Happened Between October and December 2024, attackers used stolen npm credentials to publish malicious versions of over 400 packages. These releases contained a variant of the Mini Shai-Hulud cre
IncidentBetween July 11 and August 2, someone uploaded trojanized AI agent skills to the skills.sh marketplace. By the time Zenity s research team flagged them, these malicious skills had been downloaded over
IncidentSecurity researchers at Oligo Security have uncovered a threat actor, TeamPCP, that has been active since 2020. Initially targeting infrastructure like Redis, Docker, and Kubernetes, they ve now shift