Ricerca · 63 giorni fa
Il punto non è un nuovo bug nel pull request: è che un testo che il reviewer non vede può comunque entrare nell’agent e fargli usare le sue credenziali Azure DevOps oltre il progetto aperto. La verifica umana e ciò che legge il modello non coincidono più, e il perimetro reale diventa l’accesso stabile del reviewer, non il singolo PR.
Manifold Security ha mostrato che un commento HTML nascosto nella descrizione del PR sparisce dalla UI ma torna grezzo via API, così l’agent lo tratta come istruzione. Microsoft aveva già introdotto un guardrail per altri tool del server Azure DevOps MCP, ma non per il path che restituisce i pull request; da lì un review agent può raggiungere source code, secrets e work items con i permessi dell’utente. Separatamente, Google ha portato CodeMender da progetto di ricerca a managed enterprise agent, segno che questi sistemi stanno entrando nei flussi operativi reali.
Il rischio prospettico è un canale opaco dentro i workflow di review: contenuti apparentemente innocui possono diventare comandi eseguibili per l’AI e attraversare i confini tra progetti con l’autorizzazione di chi sta facendo la verifica. Dove gli agent hanno accesso live a PR, pipeline, wiki o work items, la domanda non è più solo cosa c’è nel cambiamento, ma cosa può raggiungere l’agent con le credenziali di chi lo sta usando.
14 fonti che coprono questa storia
How AI is Rewriting the Zero-Day Playbook for Preemptive Security
Rapid7 is previewing a series of new features at Black Hat USA 2026 designed to transform the way security teams navigate the chaos of a zero-day threat to identify and close attack paths before they are exploited.
What Is AI Pentesting and How Does It Works? | Snyk
Here's how it works, what it finds, and how to evaluate it.
The most vulnerable AI products are also some of the most commonly exposed online
It is becoming increasingly easy for hackers to target vulnerable AI tools on companies’ networks, even as those companies come to depend on them for more tasks.
How enterprise GenAI can amplify ransomware risk — and how to contain it
Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled ransomware risk while supporting secure AI adoption.
Google Makes CodeMender Available as Managed AI Security Agent
CodeMender actively builds and runs exploits in customer-managed sandboxes to verify if vulnerabilities are truly exploitable
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
A hidden Azure DevOps PR comment can steer a reviewer’s AI agent into other projects and expose source code, secrets, and work items.
AI models keep getting caught cheating
Research from the UK’s AI Security Institute reveals top AI models cheat, break rules, and trick users to complete tasks—even bypassing security controls.
Manual Patching Can’t Outrun AI - Automated Remediation | Qualys
Microsoft’s July 2026 Patch Tuesday hit a record 622 vulnerabilities. AI is accelerating discovery faster than teams can patch. Learn how TruRisk Eliminate enables safe, autonomous remediation.
AI agents tricked into recommending malicious GitHub repositories - Help Net Security
7,600 malicious GitHub repositories posed as AI Skills and MCP servers, tricking Claude Code, Gemini, and ChatGPT into recommending malware.
Choose Wisely: AI-Generated Coding Risk Varies, a Lot
AI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the model used.
AI agent config attacks: How attackers turn trusted Dev harness files into payloads
Defend AI coding assistants against config attacks. Learn how attackers weaponize trusted dev harness files for supply chain exploitation, and explore 7 ways to protect your organization.
Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool
The agentic security tool identifies potentially exploitable code flaws, traces attack paths, and recommends targeted remediations.
Part of the PlainSec briefing for 2026-07-21