Remember when black-hat SEOs stuffed web pages with white-on-white keywords—invisible to readers, readable to Google—to game the search rankings? Hackers are doing the same thing with AI models now. The attacker hides instructions inside a PDF document, the model can't tell the difference between the user's words and the planted ones, and it obeys.
The eye can’t see it, but an Agent recognizes that text as another text in the document. That prompt tells Rovo to gather sensitive data and paste it onto an attacker-controlled URL. The firm calls it a zero-click attack. There’s no approval click, and no warning.
Rovo AI assistant getting hijacked. Screenshot: PromptArmor PromptArmor says the leak "succeeds even if an organization has disabled web search for Rovo. This is because the web search setting fails to remove the tool for opening the search results." Turn the feature off, and the door stays open.
Rovo AI assistant getting hijacked. Screenshot: PromptArmor Atlassian processed the report and thanked PromptArmor, the firm says, then went silent. Rovo, PromptArmor concludes, "remains vulnerable."
"Atlassian assigned a case number and expressed thanks, but after multiple follow-ups by PromptArmor over more than two months, Atlassian has made no further communication, and Rovo remains vulnerable," the firm wrote.


















