A hidden Azure DevOps PR comment can steer a reviewer’s AI agent into other projects and expose source code, secrets, and work items.
Microsoft says they are investigating claims that the Lapsus$ data extortion hacking group breached their internal Azure DevOps source code repositories and stolen data. Unlike many extortion groups ...