Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Azure DevOps Flaw Risks AI Agent Security

Azure DevOps Flaw Risks AI Agent Security

Posted on July 22, 2026 By CWS

A newly uncovered vulnerability in Microsoft’s Azure DevOps MCP server reveals a method for exploiting AI coding assistants through hidden comments in pull requests. This flaw could potentially turn these agents into tools for data exfiltration without the knowledge of the developers involved.

Discovery of the Vulnerability

Manifold Security researchers identified that the flaw allows attackers with access to a single project to manipulate a victim’s AI agent, enabling unauthorized data access from projects otherwise inaccessible. Azure DevOps MCP server integrates various tools, including pull requests and pipelines, that AI agents can access on behalf of users.

The vulnerability arises because Azure DevOps PR descriptions permit Markdown, which attackers can exploit by embedding hidden HTML comments. These comments are unseen in the web interface but are processed by the API, allowing them to manipulate the agent’s actions without detection.

Implications of the Flaw

In a demonstration, researchers showed how a hidden comment could instruct an agent to approve a pull request, initiate a pipeline in a separate project, extract confidential information, and communicate it back to the attacker. This occurs without the human reviewer’s awareness, as the agent uses the victim’s credentials to perform these actions.

This situation exemplifies a ‘confused deputy’ problem whereby an authorized agent is misled into misusing its privileges. The attack is effective because reviewers generally have more extensive access than contributors, and the attacker leverages this access through invisible instructions.

Defensive Measures and Recommendations

Microsoft had previously implemented a defense mechanism called ‘spotlighting’ to differentiate between data and instructions. However, this safeguard was not applied to pull request descriptions, leaving an exploitable entry point for attackers.

Manifold Security reported the issue to Microsoft, which acknowledged the problem but has not yet assigned a CVE or released a fix. The vulnerability aligns with Simon Willison’s ‘lethal trifecta’ framework, highlighting the risks of AI agents exposed to private data and untrusted input with a data exfiltration channel.

Strategies for Security Teams

Security teams managing MCP-connected agents should take several precautions. These include restricting agent tokens to the minimum necessary privileges, ensuring tools are loaded strictly as needed, excluding non-essential functions from code review tools, and auditing PR descriptions for hidden comments.

Ultimately, the research underscores the importance of continuous visibility in agent-driven automation, as each authorized action can become dangerous through unintended sequences and hidden intents.

Cyber Security News Tags:agentic risk, AI security, Azure DevOps, confused deputy, Cybersecurity, data exfiltration, data protection, Manifold Security, Microsoft, software vulnerability

Post navigation

Previous Post: Fourth SharePoint Security Flaw Exploited in Recent Attacks
Next Post: OpenAI’s AI Models Cause Hugging Face Security Breach

Related Posts

Oracle Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack Oracle Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack Cyber Security News
Malicious Ads Deploy FlutterShell Backdoor on macOS Malicious Ads Deploy FlutterShell Backdoor on macOS Cyber Security News
GolangGhost Malware Targets Crypto Professionals GolangGhost Malware Targets Crypto Professionals Cyber Security News
Canva, Atlassian, Epic Games Among the 100+ Enterprises Targeted by ShinyHunters Group Canva, Atlassian, Epic Games Among the 100+ Enterprises Targeted by ShinyHunters Group Cyber Security News
New Banking Malware DoubleTrouble Attacking Users Via Phishing Sites To Steal Banking Credentials New Banking Malware DoubleTrouble Attacking Users Via Phishing Sites To Steal Banking Credentials Cyber Security News
AMD Warns of Transient Scheduler Attacks Affecting Wide Range of Chipsets AMD Warns of Transient Scheduler Attacks Affecting Wide Range of Chipsets Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • NULLZEREPTOOL Utilizes Telegram for Advanced DDoS
  • OpenAI’s AI Models Cause Hugging Face Security Breach
  • Azure DevOps Flaw Risks AI Agent Security
  • Fourth SharePoint Security Flaw Exploited in Recent Attacks
  • Enhancing SOCs with Multi-Layered Detection Strategies

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • NULLZEREPTOOL Utilizes Telegram for Advanced DDoS
  • OpenAI’s AI Models Cause Hugging Face Security Breach
  • Azure DevOps Flaw Risks AI Agent Security
  • Fourth SharePoint Security Flaw Exploited in Recent Attacks
  • Enhancing SOCs with Multi-Layered Detection Strategies

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark