Azure DevOps MCP Flaw Exposes AI Agents
Manifold Security disclosed on July 21 that hidden HTML comments in Azure DevOps pull-request descriptions can inject instructions into AI agents using Microsoft's official MCP server, enabling cross-…
Manifold Security disclosed on July 21 that hidden HTML comments in Azure DevOps pull-request descriptions can inject instructions into AI agents using Microsoft's official MCP server, enabling cross-…
Four research teams demonstrated in July 2026 that AI agents share a fundamental security flaw: they trust inputs without verification. Manifold Security showed that Anthropic's Claude for Chrome can …
Security researchers at Manifold Security confirmed a trust-boundary flaw in Anthropic's Claude for Chrome extension, which reached general availability on July 1, that lets any rogue Chrome extension…
Two vulnerabilities in Anthropic's Claude for Chrome extension remain exploitable months after being reported, according to Manifold Security. The flaws allow a malicious browser extension to trigger …
Google announced the first 33 startups selected for its Gemini Startup Forum: Cybersecurity program, which focuses on AI-native cybersecurity solutions. The cohort includes companies like Capsule Secu…
Twenty-three code-executing plugins on ClawHub, an AI agent registry, were found squatting under official @openclaw and @clawhub scopes because those scopes were not reserved for their owners, exposin…
Manifold Security has added security scores for over 7,700 MCP (Model Context Protocol) servers to its supply chain intelligence platform, highlighting a critical security gap. It warns that the rapid…