A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The flaw
// analyst note
This briefing summarises reporting from The Hacker News. 90@! Ltd curates and rewrites third-party cybersecurity reporting for UK defenders. For the full technical write-up, read the original source.
Curated by 90@! Ltd from The Hacker News. Read the original for full technical detail.
Read original at The Hacker News// 90@! Ltd
90@! Ltd is a UK applications and cybersecurity consultancy. We help teams triage, remediate, and harden against emerging threats like this one.
Start an engagement