MAD A.I CyberSecurity Scoring
MAD
Company Information
Website:https://azure.com/devops
Employees number:147
Number of followers:0
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:azure.com
MAD Risk Score (AI oriented)
Between 800 and 849
MADIT Services and IT Consulting
Updated:
22/07/2026
22/07/2026
822/1000
Good
A
MAD Global Score (TPRM)
xxxx
MADIT Services and IT Consulting
Score locked

MADGood
Current Score
822A (GOOD)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
822
JULY 2026
821
Vulnerability
22 Jul 2026 • MAD
Microsoft: Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data
Azure DevOps MCP Flaw Enables Silent Data Theft via AI Coding Assistants
822
CRITICAL-1
MIC1784715975
Azure DevOps MCP Flaw Enables Silent Data Theft via AI Coding Assistants
Security researchers at Manifold Security uncovered a critical vulnerability in Microsoft’s Azure DevOps MCP server that allows attackers to hijack AI coding assistants and exfiltrate sensitive data from restricted projects. The flaw exploits hidden HTML comments in pull request (PR) descriptions content invisible in the web interface but readable via API to perform indirect prompt injection.
When a victim’s AI agent reviews a malicious PR, it unknowingly executes embedded instructions, such as approving the PR, triggering pipelines in unrelated projects (e.g., "Payments"), and extracting confidential wiki pages. The stolen data is then posted as a PR comment, accessible to the attacker. Since the agent operates under the victim’s credentials, it bypasses access controls, enabling attackers to reach data they couldn’t access directly a classic "confused deputy" attack.
Microsoft had previously implemented "spotlighting" a defense that wraps untrusted content in delimiters to mitigate such risks. However, the fix was applied to pipeline and wiki tools but not PR descriptions, leaving the attack vector open. Manifold Security reported the issue to Microsoft’s Security Response Center, which acknowledged it, though no CVE has been assigned or patch released as of publication.
The incident aligns with Simon Willison’s "lethal trifecta" framework for AI agent risks: access to private data, exposure to untrusted content, and an exfiltration channel. Researchers emphasize that while each agent action appears authorized, the hidden intent and sequence of commands create the threat. The attack highlights the need for continuous monitoring of AI-driven automation, as traditional code audits may miss dynamic, context-aware exploits.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
821
MAY 2026
821
APRIL 2026
819
MARCH 2026
819
FEBRUARY 2026
819
JANUARY 2026
819
DECEMBER 2025
819
NOVEMBER 2025
819
OCTOBER 2025
819
SEPTEMBER 2025
819
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for MAD ??
What was MAD's A.I Rankiteo Cyber Score in July 2026 ??
What was MAD's A.I Rankiteo Cyber Score in June 2026 ??
What was MAD's A.I Rankiteo Cyber Score in May 2026 ??
What was MAD's A.I Rankiteo Cyber Score in April 2026 ??
What was MAD's A.I Rankiteo Cyber Score in March 2026 ??
What was MAD's A.I Rankiteo Cyber Score in February 2026 ??
What was MAD's A.I Rankiteo Cyber Score in January 2026 ??
What was MAD's A.I Rankiteo Cyber Score in December 2025 ??
What was MAD's A.I Rankiteo Cyber Score in November 2025 ??
What was MAD's A.I Rankiteo Cyber Score in October 2025 ??
What was MAD's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on MAD's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with MAD ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view MAD's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?