Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

2026-08-08T19:23:59Z35387591f4afc1dbc27fd583fd2134184769cb77d5f2d9942d30b9065c6c504f
CVE-2026-64561CVE-2026-64638CVE-2026-8037AiTMCISA-KEVEntra-IDRATactive-exploitationcommand-injectioncontainer-escapedata-exfiltrationidentityinfostealerkernelmacOS-stealer-crypto-wallets,malwarenpm-supply-chainphishingprivilege-escalationprompt-injectionrcesql-injectionvishingvm-escapevulnerabilitywebmailxsszero-day

What happened

The document aggregates cybersecurity news covering actively exploited vulnerabilities, zero-days, malware and supply-chain campaigns, phishing, AI prompt-injection risks, cloud and identity attacks, web and kernel flaws, and exposed industrial systems. Several items describe critical or high-impact threats, including unauthenticated Metabase compromise, CISA-listed Kemp LoadMaster command injection (CVE-2026-8037), WordPress pre-authentication XSS leading to potential PHP execution (CVE-2026-64638), Linux and KVM container or VM escapes, malicious npm packages, and active Microsoft 365 and Rò

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
35387591f4afc1dbc27fd583fd2134184769cb77d5f2d9942d30b9065c6c504f
Enrichment time
2026-08-08T19:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.