Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data

A newly disclosed flaw in Microsoft’s official Azure DevOps MCP server shows how an invisible comment in a pull request can silently hijack a developer’s AI coding assistant and turn it into a data-exfiltration tool. Security researchers at Manifold Security found that the bug lets an attacker with access to just one project steer a […]

The post Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: