Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hidden Comment Flaw in Azure DevOps Risks AI Exploitation

Hidden Comment Flaw in Azure DevOps Risks AI Exploitation

Posted on July 22, 2026 By CWS

An invisible comment within Azure DevOps pull requests poses a significant security risk, allowing attackers to manipulate AI agents into accessing unauthorized projects and discreetly leaking sensitive information. This flaw has been identified in Microsoft’s Azure DevOps MCP server, where a missing security measure leaves AI tools vulnerable to exploitation.

Understanding the Vulnerability

The security gap was highlighted by Manifold Security, an offensive security firm, which labeled the issue as a ‘confused-deputy’ bug. Microsoft’s server enables AI agents to access various DevOps functionalities, including pull requests, pipelines, and wikis, using the user’s own permissions. The problem arises when content created by others becomes actionable instructions for these AI agents.

Mechanism of the Exploit

Pull request descriptions in Azure DevOps accommodate Markdown, which supports HTML comments. These comments appear invisible in the web interface but are delivered verbatim via the REST API to the AI agent. This discrepancy allows attackers to embed hidden instructions within pull requests. As a result, when a reviewer uses an AI agent for review, the concealed comments can redirect the agent’s tasks, leveraging the reviewer’s credentials to access unauthorized data.

Implications and Mitigations

The flaw enables unauthorized access to source code, secrets, and work items, which the attacker can exploit without direct access. Manifold’s proof of concept demonstrated how a hidden comment could trigger unauthorized actions across different projects. Despite existing defenses, such as spotlighting, the pull request path lacks sufficient protection. Microsoft has acknowledged the risk and suggested limiting project access and reviewing changes before AI tool engagement.

Future Outlook and Recommendations

While Microsoft continues to enhance its security measures, the flaw highlights the importance of rigorous content review and AI agent management. Organizations are advised to implement least-privilege access for AI agents and restrict project scope to minimize exposure. As automated review processes become more prevalent, ensuring that AI tools are protected against such vulnerabilities is crucial for maintaining data integrity and security.

In light of these findings, maintaining vigilant security practices and regularly auditing AI tool interactions is essential to prevent unauthorized data exposure. This incident underscores the need for ongoing security evaluations as the landscape of AI-driven tools evolves.

The Hacker News Tags:AI agents, AI security, Azure DevOps, Cybersecurity, DevOps, Manifold Security, Microsoft, prompt injection, security risk, software vulnerabilities

Post navigation

Previous Post: Trojanized NuGet Package Alters Online Betting Results
Next Post: GolangGhost Malware Targets Crypto Professionals

Related Posts

Microsoft Addresses GitHub Security Breach Amid Ongoing Probe Microsoft Addresses GitHub Security Breach Amid Ongoing Probe The Hacker News
Espionage Campaigns Target Pakistani Police Portals Espionage Campaigns Target Pakistani Police Portals The Hacker News
Shai-Hulud v2 Campaign Spreads From npm to Maven, Exposing Thousands of Secrets Shai-Hulud v2 Campaign Spreads From npm to Maven, Exposing Thousands of Secrets The Hacker News
CISA Adds Actively Exploited VMware vCenter Flaw CVE-2024-37079 to KEV Catalog CISA Adds Actively Exploited VMware vCenter Flaw CVE-2024-37079 to KEV Catalog The Hacker News
Researchers Spot Surge in Erlang/OTP SSH RCE Exploits, 70% Target OT Firewalls Researchers Spot Surge in Erlang/OTP SSH RCE Exploits, 70% Target OT Firewalls The Hacker News
Google Warns of Scattered Spider Attacks Targeting IT Support Teams at U.S. Insurance Firms Google Warns of Scattered Spider Attacks Targeting IT Support Teams at U.S. Insurance Firms The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical ServiceNow Flaw Under Active Exploitation
  • Oracle Enhances Security with Over 1,400 Patches
  • OpenAI AI Models Breach Security, Target Hugging Face
  • AccuKnox Secures Top AI Startup Award for Security Excellence
  • Coca-Cola’s Fairlife Hit by Anubis Ransomware Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical ServiceNow Flaw Under Active Exploitation
  • Oracle Enhances Security with Over 1,400 Patches
  • OpenAI AI Models Breach Security, Target Hugging Face
  • AccuKnox Secures Top AI Startup Award for Security Excellence
  • Coca-Cola’s Fairlife Hit by Anubis Ransomware Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark