Threat Brief — 2026-07-22 — AI Agents Turn Against Their Owners
Executive summary: A flaw in Microsoft's Azure DevOps MCP lets attackers hijack AI code-review agents via invisible pull-request comments — the most significant new finding, as it weaponises the AI-assisted development pipeline itself. Kaspersky disclosed a passwordless Microsoft 365 takeover technique ("ConsentFix"), and the Awaken Likho APT resurfaced with a new AutoIt backdoor for targeted espionage. A trojanized Newtonsoft.Json NuGet package and a fresh NGINX SSI module vulnerability round out the actionable items.
Top items
- Azure DevOps MCP flaw lets hidden PR comments hijack AI coding agents. A single invisible comment in an Azure DevOps pull request can redirect a reviewer's own AI agent into attacker-controlled projects and silently exfiltrate findings. Exploitable via Microsoft's MCP integration; any team running automated AI code review is at risk. (src: The Hacker News)
- ConsentFix technique enables passwordless Microsoft 365 account takeover. Kaspersky discovered a method that grants attackers access to M365 mailboxes without stealing any password — abusing OAuth consent flows. No credentials are compromised, yet full mailbox access is achieved. (src: SecurityLab)
- Awaken Likho APT deploys new AutoIt backdoor for targeted attacks in Russia. Kaspersky reports the group has shifted tactics, preparing a mini-backdoor written in AutoIt alongside updated C2 infrastructure — indicating renewed operational tempo. (src: Securelist)
- Trojanized Newtonsoft.Json NuGet fork hides game-rigging code in a working library. Unlike typical info-stealing typosquats, this package is designed to rig live game results on Digitain — a novel supply-chain attack motive. The package is functional, making detection harder. (src: The Hacker News)
- Second NGINX vulnerability disclosed: SSI module flaw (CVE-2026-56434). Distinct from the already-reported CVE-2026-42533 map directive heap overflow, this new SSI module vulnerability adds another attack surface on NGINX deployments. (src: MSRC)
- Libarchive heap overflow and syslog-ng SQL injection disclosed. Libarchive (CVE-2026-15028) suffers an OOB read when parsing tar pax extended headers; syslog-ng's SQL destination driver (CVE-2026-39879) has a SQL injection flaw. Both are parsing-layer issues affecting widely deployed infrastructure components. (src: MSRC — Libarchive, MSRC — syslog-ng)
- Chick-fil-A discloses customer data breach from credential stuffing. The fast-food chain is notifying customers after a wave of credential stuffing attacks compromised user accounts. (src: BleepingComputer)
Themes
AI agents as both attack vector and target. The Azure DevOps MCP hijack and Claude Cowork's new screen-recording training feature (id 4018) highlight a widening attack surface: AI agents now handle privileged dev workflows and ingest sensitive user behaviour data, but their input channels remain insufficiently guarded. This builds on the pattern seen in last week's sandbox-escape and invisible-text-injection findings.
Supply-chain attacks diversify in motive. The trojanized Newtonsoft.Json package — aimed at game rigging rather than data theft — demonstrates that package-registry abuse is branching beyond traditional info-stealer payloads, making motive prediction and detection harder for defenders.
===
