CyberHighConfirmedAccelerating
10.0
Microsoft patches Azure Automation flaw enabling cross-tenant identity takeover
Dark Reading·US·about 5 hours ago
A security flaw in Azure DevOps' Model Context Protocol (MCP) implementation allows attackers to bypass permission controls by manipulating AI coding agents. By injecting hidden comments into pull requests, an attacker can trick an AI agent into accessing and leaking data from projects outside the reviewer's authorized scope.