“A single click on a link triggers the attacker’s embedded instructions and forces Rovo to accept externally supplied parameters as trusted inputs within a user’s session.”
Varonis got Atlassian’s assistant to treat a URL parameter as instructions, then used Rovo’s own automation to drain Jira, Confluence, Bitbucket, Slack, Google Workspace and 50-odd other connected systems. One click. Atlassian patched it and paid out through Bugcrowd, which closes this bug and nothing else. The pattern is the product: wire an agent into every system a company owns, then hope none of the text it reads is hostile.