A single invisible comment in an Azure DevOps pull request can
turn a reviewer's own AI coding agent against them, driving it into
projects the attacker has no rights to reach and quietly leaking
what it finds. The flaw is in Microsoft's official Azure DevOps MCP
server, and it works because one of its tools returns pull request
descriptions without a prompt-injection guardrail the company
had
Read more https://thehackernews.com/2026/07/microsoft-azure-devops-mcp-flaw-lets.html

