
Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data
A newly disclosed flaw in Microsoft’s official Azure DevOps MCP server shows how an invisible comment in a pull request can silently hijack a developer’s AI coding assistant and turn it into a data-exfiltration tool. Security researchers at Manifold Security found that the bug lets an attacker with access to just one project steer a […]
The post Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data appeared first on Cyber Security News.