A vulnerability in Microsoft Azure DevOps allows attackers to embed hidden commands in pull request comments that can manipulate AI review agents into approving malicious code or executing unintended actions. Organizations using AI-powered code review too
Read the full article: https://thehackernews.com/2026/07/microsoft-azure-devops-mcp-flaw-lets.html