Threat Brief — 2026-08-18 — Copilot meta-hacking, cloud-cred raids, and ransom double-crosses
A "CoSnitch" meta-hacking technique tricked Microsoft Copilot into revealing its own architecture and connected-app data via three Varonis-disclosed vulnerabilities (CVE-2026-24301), expanding the attack surface beyond the original MSRC advisory. Meanwhile, active exploitation of MLflow's SSRF flaw is being used to harvest cloud credentials, and a ransomware affiliate is posing as an incident-recovery service to charge victims $20K–$60K for data "deletion." A major RuNet outage and a crypto-broker breach round out a busy day.
Top items
- Microsoft Copilot "CoSnitch" attack — three vulnerabilities enable one-click data exfiltration. Varonis Threat Labs disclosed three flaws in Microsoft Copilot Personal (tracked under CVE-2026-24301), including a "meta-hacking" technique dubbed "CoSnitch" that manipulates the AI service into mapping out its own architecture and revealing security weaknesses. A single click on a crafted link can silently pull data from connected apps and other information available to the victim's Copilot context. This is a developing story: MSRC first published the CVE on 2026-08-18 (src: MSRC); today's Varonis research adds the CoSnitch meta-hacking vector and connected-app exfiltration details (src: Dark Reading), (src: The Hacker News)
- MLflow SSRF actively exploited for cloud credential and secret theft. Attackers are exploiting a critical SSRF vulnerability in MLflow (open-source AI platform) alongside a related flaw in FUXA (web-based SCADA/HMI software) to steal cloud credentials and secrets from exposed instances. Any team running MLflow or FUXA with internet-facing deployments should treat cloud secrets as potentially compromised and rotate immediately. First reported 2026-08-18 (src: The Hacker News)
- "Ransom Busters" affiliate charges victims $20K–$60K to "recover" stolen data. A ransomware affiliate calling itself Ransom Busters is proactively emailing victim organizations, claiming it has hacked ransomware-group servers and will delete stolen data for a fee of $20,000–$60,000. The scheme is effectively a secondary extortion layer — victims may pay thinking they're recovering data while the affiliate either has no real ability to deliver or is simply diverting ransom payments. First reported 2026-08-18 (src: The Hacker News), (src: Dark Reading)
- Major RuNet outage: Moscow power accident and Reg.ru crash take thousands of sites offline. A power incident at Moscow's TÉTS-20 (CHPP-20) knocked out infrastructure in the M9 area, causing a Reg.ru hosting crash that took thousands of Russian websites offline — described as the largest RuNet outage on record. First reported 2026-08-18 (src: SecurityLab.ru)
- Israel's largest crypto broker Bits of Gold investigates data breach. A breach at a third-party support provider exposed customer data from Bits of Gold, which serves 300,000 clients with only 55 employees. The incident underscores supply-chain risk concentration in crypto platforms with lean staffing. First reported 2026-08-18 (src: SecurityLab.ru)
Themes
AI is becoming both target and weapon. The Copilot CoSnitch research and the MLflow SSRF exploitation both demonstrate that AI-adjacent infrastructure — from copilots to MLOps platforms — is now a primary attack vector for data exfiltration and credential theft. The pattern is consistent: AI tools with broad data access and insufficient input validation create high-value, low-effort targets.
Ransomware ecosystem diversification. The Ransom Busters scheme shows threat actors innovating not just on encryption but on the extortion and "recovery" business model itself — inserting themselves between victims and legitimate incident response to extract a second payment.
