Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Microsoft Azure DevOps

Microsoft Azure DevOps Vendor Cyber Rating & Cyber Score

azure.com

Azure DevOps is a set of developer and DevOps tools and services from Microsoft Azure.


MAD A.I CyberSecurity Scoring

MAD
Company Information
Website:https://azure.com/devops
Employees number:147
Number of followers:0
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:azure.com
MAD Risk Score (AI oriented)
Between 800 and 849
logo
MADIT Services and IT Consulting
Updated:
22/07/2026
822/1000
Good
A
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
MAD Global Score (TPRM)
xxxx
logo
MADIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

MAD
MADGood
Current Score
822A (GOOD)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
822Before Incident
JULY 2026
821Before Incident
Vulnerability
22 Jul 2026MAD
Microsoft: Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data

Azure DevOps MCP Flaw Enables Silent Data Theft via AI Coding Assistants

822After Incident
CRITICAL-1
MIC1784715975
Azure DevOps MCP Flaw Enables Silent Data Theft via AI Coding Assistants Security researchers at Manifold Security uncovered a critical vulnerability in Microsoft’s Azure DevOps MCP server that allows attackers to hijack AI coding assistants and exfiltrate sensitive data from restricted projects. The flaw exploits hidden HTML comments in pull request (PR) descriptions content invisible in the web interface but readable via API to perform indirect prompt injection. When a victim’s AI agent reviews a malicious PR, it unknowingly executes embedded instructions, such as approving the PR, triggering pipelines in unrelated projects (e.g., "Payments"), and extracting confidential wiki pages. The stolen data is then posted as a PR comment, accessible to the attacker. Since the agent operates under the victim’s credentials, it bypasses access controls, enabling attackers to reach data they couldn’t access directly a classic "confused deputy" attack. Microsoft had previously implemented "spotlighting" a defense that wraps untrusted content in delimiters to mitigate such risks. However, the fix was applied to pipeline and wiki tools but not PR descriptions, leaving the attack vector open. Manifold Security reported the issue to Microsoft’s Security Response Center, which acknowledged it, though no CVE has been assigned or patch released as of publication. The incident aligns with Simon Willison’s "lethal trifecta" framework for AI agent risks: access to private data, exposure to untrusted content, and an exfiltration channel. Researchers emphasize that while each agent action appears authorized, the hidden intent and sequence of commands create the threat. The attack highlights the need for continuous monitoring of AI-driven automation, as traditional code audits may miss dynamic, context-aware exploits.
INCIDENT DETAILS -
TYPE
Data Exfiltration
IMPACT
Data Compromised: Sensitive data from restricted projects, confidential wiki pagesSystems Affected: Azure DevOps MCP server, AI coding assistantsOperational Impact: Unauthorized data access and exfiltration, potential pipeline triggers in unrelated projectsBrand Reputation Impact: Potential reputational damage due to vulnerability exposure
DATA BREACH
Type Of Data Compromised: Sensitive project data, confidential wiki pagesSensitivity Of Data: High (restricted projects, confidential information)
JUNE 2026
821Before Incident
MAY 2026
821Before Incident
APRIL 2026
819Before Incident
MARCH 2026
819Before Incident
FEBRUARY 2026
819Before Incident
JANUARY 2026
819Before Incident
DECEMBER 2025
819Before Incident
NOVEMBER 2025
819Before Incident
OCTOBER 2025
819Before Incident
SEPTEMBER 2025
819Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for MAD ?
?
What was MAD's A.I Rankiteo Cyber Score in July 2026 ?
?
What was MAD's A.I Rankiteo Cyber Score in June 2026 ?
?
What was MAD's A.I Rankiteo Cyber Score in May 2026 ?
?
What was MAD's A.I Rankiteo Cyber Score in April 2026 ?
?
What was MAD's A.I Rankiteo Cyber Score in March 2026 ?
?
What was MAD's A.I Rankiteo Cyber Score in February 2026 ?
?
What was MAD's A.I Rankiteo Cyber Score in January 2026 ?
?
What was MAD's A.I Rankiteo Cyber Score in December 2025 ?
?
What was MAD's A.I Rankiteo Cyber Score in November 2025 ?
?
What was MAD's A.I Rankiteo Cyber Score in October 2025 ?
?
What was MAD's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on MAD's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with MAD ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view MAD's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?