Security
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
The Hacker News·July 22, 2026·1 min read
A flaw in Microsoft's official Azure DevOps MCP server allows a single invisible comment in a pull request to turn an AI coding agent against its user. The vulnerability enables attackers to access projects they lack rights to and leak findings. The issue stems from a tool returning descriptions without a prompt-injection guardrail Microsoft had implemented.
Read at The Hacker NewsDaily crypto arcade
Read the news, then play it.
Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.
