threat-intel Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents A vulnerability in Microsoft Azure DevOps's MCP server allows attackers to hijack AI coding agents by inserting hidden HTML comments in pull requests. These comments can then instruct the agent to perform actions – like accessing secret wiki pages and triggering pipelines in other projects – that the reviewer would nev… The Hacker News · Jul 22, 2026 High prompt-injectionai-riskmicrosoft