Utopia Tech
▸ Engineering & Strategy Journal

Field notes from the edge.

What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersAI
Security

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Security researchers have discovered vulnerabilities in Atlassian's Rovo AI assistant that allow attackers to extract sensitive Jira and Confluence data accessible to authenticated users by injecting malicious instructions. Two security firms independently identified different attack vectors, with only one confirmed as patched. The exploit involves embedding attacker-controlled prompts in content

UTUtopia Tech·1 min
CSS: The Hidden Threat Lurking in Your InboxAI
Security

CSS: The Hidden Threat Lurking in Your Inbox

Security researchers have identified CSS as an emerging threat vector for data exfiltration in webmail environments, moving beyond its traditional design-focused role. The vulnerability exploits CSS capabilities to extract sensitive information from email clients, with some vendors lacking adequate protections against these attacks.

UTUtopia Tech·1 min
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer DataAI
Security

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

Open VSX marketplace removed 77 malicious extensions that impersonated legitimate developer tools to exfiltrate data about developers' systems and environments. The 'evil twin' extensions were uploaded between July 26 and August 1, 2026, and have since been removed following discovery by Manifold Security.

UTUtopia Tech·1 min
Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense EmailsAI
Security

Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails

A Chinese state-linked threat actor compromised North American medical, academic, and military research organizations for over a year by exploiting REDCap research servers to steal credentials. The attackers then manipulated victims' Google Workspace email forwarding rules to exfiltrate sensitive research and defense communications, demonstrating an innovative persistence and data theft technique

UTUtopia Tech·1 min
One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA CodesAI
Security

One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes

Security researchers at Varonis Threat Labs discovered a critical vulnerability chain called SearchLeak that could allow attackers to exfiltrate sensitive data from Microsoft 365 Copilot Enterprise Search through a single click on a legitimate Microsoft domain link. The attack bypassed traditional security controls because it used authentic microsoft.com URLs, making it difficult for anti-phishing

UTUtopia Tech·1 min
Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five MonthsAI
Security

Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months

Cybercriminals conducted a sophisticated five-month espionage operation targeting a senior executive at a major global stock exchange, exfiltrating email data through legitimate cloud services like Dropbox and OneDrive to evade detection. The attackers used small, repeated data transfers that mimicked normal cloud traffic patterns, demonstrating advanced tradecraft focused on intelligence gatherin

UTUtopia Tech·1 min
Skip to main content