Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
A critical vulnerability in Microsoft's official Azure DevOps MCP server allows attackers to inject hidden HTML comments into pull request descriptions, which…
A critical vulnerability in Microsoft's official Azure DevOps MCP server allows attackers to inject hidden HTML comments into pull request descriptions, which…
A critical vulnerability in AWS Kiro, an agentic coding IDE, allowed a poisoned web page to rewrite its configuration file and execute…
A new class of attack called Agent Data Injection (ADI) has been disclosed by researchers from Seoul National University, the University of…
OpenAI has disclosed details of GPT-Red, an internal automated red-teaming model that scales prompt injection vulnerability discovery to fix issues before tools…
GPT-Red is an internal automated red-teaming model that scales prompt injection vulnerability discovery by iteratively sending prompts and monitoring responses to achieve…
GPT-5.1 was found to be highly vulnerable to Fake Chain-of-Thought (CoT) attacks, with success rates above 95%, but now below 10% for…
Researchers at Manifold Security have disclosed two vulnerabilities in the Claude for Chrome browser extension that could allow rogue extensions to trigger…
A new attack named MemGhost demonstrates how a single email can inject persistent false memories into AI personal assistants, manipulating their future…
GitHub Copilot CLI was successfully used in Manifold Security's proof of concept to demonstrate the Azure DevOps MCP server vulnerability, showing the…
Researchers from Tel Aviv University, Technion, and Intuit have identified a novel attack vector called HalluSquatting that exploits AI coding assistants' tendency…