← Back to KHAO

Google · AI Agent · GPT ·

The attacker hides instructions inside a PDF document, the model can't tell the difference between the user's words

2 min read

Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.

★ Tier-1 Source

Hacks are a problem in AI as much as in crypto.

Remember when black-hat SEOs stuffed web pages with white-on-white keywords—invisible to readers, readable to Google—to game the search rankings?

Key facts

Summary

Security company PromptArmor says the Rovo AI assistant can be steered to exfiltrate data with no human approval, via hidden instructions in an uploaded file, like PDFs. The trick works even when an org disables Rovo's web search, because the URL-opening tool stays live. Atlassian, the maker of Rovo, got the report on May 23 and went quiet; two months on, Rovo "remains vulnerable," the security firm says. Per PromptArmor's disclosure, Rovo—Atlassian's agent that reaches across Jira, Confluence, and the rest of your workspace—can be turned into a data pipeline with a single poisoned file.

Read full article at Decrypt →

#Google #AI Agent #GPT