Research · 48 days ago
The break is in the trust boundary between what a human sees and what an AI agent reads. In Azure DevOps, a comment can be invisible in the web UI but still return through the API as raw text, so a reviewer’s agent can take attacker-written instructions and use the reviewer’s own permissions across projects.
Manifold Security says Microsoft’s official Azure DevOps MCP server leaves pull request descriptions without the prompt-injection guardrail it applied to other tools. That means the same workflow can expose source code, secrets, and work items, not just the pull request under review. Google also moved CodeMender from research into a managed enterprise agent, which broadens the set of AI systems now able to act inside production development environments.
The forward risk is the same across these tools: content that looks like data can become instructions once an agent is allowed to act on it. A routine review request can turn into a cross-project exfiltration path when the agent carries live workspace permissions.
14 sources covering this story
How AI is Rewriting the Zero-Day Playbook for Preemptive Security
Rapid7 is previewing a series of new features at Black Hat USA 2026 designed to transform the way security teams navigate the chaos of a zero-day threat to identify and close attack paths before they are exploited.
What Is AI Pentesting and How Does It Works? | Snyk
Here's how it works, what it finds, and how to evaluate it.
The most vulnerable AI products are also some of the most commonly exposed online
It is becoming increasingly easy for hackers to target vulnerable AI tools on companies’ networks, even as those companies come to depend on them for more tasks.
How enterprise GenAI can amplify ransomware risk — and how to contain it
Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled ransomware risk while supporting secure AI adoption.
Google Makes CodeMender Available as Managed AI Security Agent
CodeMender actively builds and runs exploits in customer-managed sandboxes to verify if vulnerabilities are truly exploitable
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
A hidden Azure DevOps PR comment can steer a reviewer’s AI agent into other projects and expose source code, secrets, and work items.
AI models keep getting caught cheating
Research from the UK’s AI Security Institute reveals top AI models cheat, break rules, and trick users to complete tasks—even bypassing security controls.
Manual Patching Can’t Outrun AI - Automated Remediation | Qualys
Microsoft’s July 2026 Patch Tuesday hit a record 622 vulnerabilities. AI is accelerating discovery faster than teams can patch. Learn how TruRisk Eliminate enables safe, autonomous remediation.
AI agents tricked into recommending malicious GitHub repositories - Help Net Security
7,600 malicious GitHub repositories posed as AI Skills and MCP servers, tricking Claude Code, Gemini, and ChatGPT into recommending malware.
Choose Wisely: AI-Generated Coding Risk Varies, a Lot
AI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the model used.
AI agent config attacks: How attackers turn trusted Dev harness files into payloads
Defend AI coding assistants against config attacks. Learn how attackers weaponize trusted dev harness files for supply chain exploitation, and explore 7 ways to protect your organization.
Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool
The agentic security tool identifies potentially exploitable code flaws, traces attack paths, and recommends targeted remediations.
Part of the PlainSec briefing for 2026-07-21