Hidden PR Comments in Azure DevOps Exploit Allows Hijacking of AI Review Agents
A security flaw in Microsoft Azure DevOps allows attackers to embed hidden comments in pull requests that can hijack AI-powered code review agents. This vulnerability could enable unauthorized code changes or malicious injections into development pipelines. It highlights risks in AI-assisted software workflows.