# MLflow Flaw and ‘CoSnitch’ Attack Chain Expose New Paths to Cloud and Copilot Data Theft

*Tuesday, August 18, 2026 at 6:06 PM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-08-18T18:06:03.248Z (3h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/14890.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Attackers are already exploiting a new SSRF flaw in MLflow (CVE-2026-64849) to steal cloud credentials, while researchers warn that a ‘CoSnitch’ attack chain could pull sensitive data from apps linked to Microsoft Copilot Personal with a single malicious link. For CISOs and defense planners, the message is blunt: AI tools and MLOps platforms are fast becoming front-line targets.

Two newly detailed attack paths are putting AI-enabled services and machine-learning infrastructure under fresh scrutiny, raising the stakes for organizations that rushed to integrate generative AI and MLOps tools into sensitive workflows. On 18 August, security researchers warned that a chain of flaws dubbed “CoSnitch” could allow a single crafted link to exfiltrate data from Microsoft Copilot Personal–connected applications, while separate reports confirmed that attackers are actively exploiting a server-side request forgery (SSRF) bug in MLflow, tracked as CVE-2026-64849, to steal cloud credentials.

The CoSnitch scenario targets users already signed in to Microsoft Copilot Personal. According to public technical write-ups, an attacker can embed a malicious prompt in a specially crafted Copilot link. When the victim opens it, Copilot automatically executes the attacker’s instructions in the context of the user’s existing session, with access to other services the user has authorized. From there, the chain can automatically pull data from connected apps — such as email, cloud storage, or productivity tools — without requiring additional clicks or obvious consent.

Microsoft has not been reported issuing a detailed public response yet, but the described behavior illustrates a broader design risk: AI assistants that can act across multiple integrated services become powerful aggregators of access. If their trust boundaries can be manipulated via links, chat prompts, or browser extensions, they offer attackers a shortcut past traditional authentication prompts and user awareness training.

The MLflow vulnerability is more traditional in form but similarly dangerous in effect. CVE-2026-64849 allows remote attackers to abuse MLflow’s handling of URLs to perform SSRF, enabling them to reach internal cloud metadata services from exposed MLflow instances. Once there, they can extract cloud access keys and tokens, effectively turning a misconfigured or unpatched MLOps deployment into a stepping stone for full cloud-account compromise. Security researchers say they detected scanning for vulnerable MLflow servers within hours of the CVE being assigned, indicating that threat actors are moving quickly to weaponize the flaw.

For security teams in governments, defense contractors, and critical industries, the operational stakes are high. MLflow is widely used to manage machine-learning experiments, models, and data pipelines; compromising it can expose not only credentials but also sensitive training data and proprietary models. Copilot-like assistants, meanwhile, are increasingly being wired into email, document repositories, and ticketing systems inside sensitive environments, including those handling national security and critical infrastructure operations.

Strategically, these incidents show that AI and machine-learning platforms are no longer niche risks but central components of the enterprise attack surface. Tools originally adopted to accelerate development or automate knowledge work now sit at the crossroads of multiple data streams; a single overlooked vulnerability can bridge gaps between systems that were once isolated. For adversaries interested in espionage, supply-chain compromise, or disruptive operations, going after the platforms that orchestrate models and AI agents may yield more value than attacking individual business applications.

A concise way to think about the shift is this: as organizations turn AI into a universal interface for their data, every flaw in that interface becomes a universal key. Hardening the underlying cloud and identity layers matters, but so does treating AI agents and MLOps consoles as high-value assets deserving of the same protection as domain controllers and code repositories.

The next indicators to watch are whether patches and mitigations are rapidly deployed for MLflow, whether cloud providers issue additional guidance or enforce protections around metadata services, and how Microsoft and other AI vendors adjust link-handling and cross-service permissioning in their assistants. Incident disclosures tying real-world breaches to these specific weaknesses would further elevate their priority, as would any signs that state-aligned actors are exploiting them against government or defense-sector targets.
