Tag
A report on Microsoft's Azure DevOps MCP server reveals a confused-deputy attack where hidden PR text can manipulate AI review agents (Copilot CLI, Claude Code) into unintended tool calls with the user's permissions. Recommendations include using read-only identities and requiring separate approval steps.
Hackers exploited Meta's AI support chatbot to steal high-value Instagram accounts by tricking it into account recovery, highlighting the dangers of AI agents with elevated permissions. Accounts with MFA were not compromised.