Detecting the Confused Deputy in Azure DevOps MCP
A hidden pull-request comment turned legitimate MCP calls into a cross-project data path. Detecting it requires source, identity, scope, sequence, and sink.
notebook / tag
2 entries with this tag.
A hidden pull-request comment turned legitimate MCP calls into a cross-project data path. Detecting it requires source, identity, scope, sequence, and sink.
A threat actor used an unattended AI agent inside a real intrusion. The useful lesson is in the evidence it added, not the capabilities it replaced.