CISO Talk by James Azar
CyberHub Podcast
MLflow Exploited Within Hours, Medusa Hits 500+ Organizations, Copilot Data-Theft Flaw Exposed & DOJ Charges 17 Iranian Hackers
0:00
-19:36

MLflow Exploited Within Hours, Medusa Hits 500+ Organizations, Copilot Data-Theft Flaw Exposed & DOJ Charges 17 Iranian Hackers

Attackers are compressing the vulnerability lifecycle from weeks to hours as cloud credentials, AI assistants, critical infrastructure and intellectual property become high-value targets

Good Morning Security Gang

I’m coming to you from the road today, so the studio looks a little different, the setup is considerably smaller, and unfortunately the double espresso isn’t joining me because my choices are Starbucks and Tim Hortons. I think we all know where I stand on that one.

But the cybersecurity news doesn’t stop because I’m traveling, and today’s show brings eleven stories that collectively point toward one unmistakable trend: the time defenders have between vulnerability disclosure and attacker exploitation continues to collapse.

Attackers began targeting a critical MLflow vulnerability within hours of its CVE assignment and are reportedly already extracting cloud credentials. CISA says a Windows privilege-escalation vulnerability patched last November is now being leveraged in ransomware attacks. Medusa ransomware has compromised more than 500 critical-infrastructure organizations and is weaponizing newly disclosed vulnerabilities in as little as 24 hours. Meanwhile, researchers found a Microsoft Copilot attack chain capable of turning a single malicious link into access to connected email, files and chat history.

Beyond those headlines, Apple has another substantial security update, UT San Antonio contained suspicious activity before attackers reached core systems, two Berlin government ministries remain disconnected following a cyberattack, Ukraine is investigating an attack against its asset recovery agency, OpenAI is tightening its AI testing infrastructure after last month’s model-escape incident, Anthropic is experimenting with statistical watermarking for Claude-generated text, and the Justice Department has charged 17 alleged Iranian hackers in a campaign that prosecutors say stole 31 terabytes of research and intellectual property.

The theme is simple: speed.

Attackers aren’t waiting for our patch cycles anymore.

Coffee cup cheers to whatever you’re drinking this morning.

Let’s get into it.

Today’s Cybersecurity Picture: Hours Are Becoming the New Days

For years, vulnerability-management programs were designed around predictable remediation windows. Critical vulnerabilities might receive seven days. High-severity issues might receive 30. Everything else could work through the normal change-management process.

Today’s stories demonstrate why that model needs another lane.

MLflow went from vulnerability disclosure to active exploitation within hours. Federal agencies say Medusa affiliates have demonstrated the ability to weaponize newly disclosed vulnerabilities in less than a day and sometimes before defenders even have patches available. A Windows vulnerability Microsoft fixed months ago is still finding enough unpatched systems to become useful to ransomware operators.

That doesn’t mean every CVE deserves an emergency change. It means exploitability and exposure have to override severity scores and calendar-based SLAs when circumstances justify it.

“We need to patch fast, watch our AI tools like privileged accounts, and not wait for the ransom note to find out we were exposed.”

MLflow Critical Vulnerability Already Exploited to Steal Cloud Credentials

We start with the most urgent vulnerability on today’s show. Attackers are already exploiting a critical vulnerability in MLflow, the widely used open-source platform for tracking machine-learning experiments, models and development workflows. The vulnerability is tracked as CVE-2026-64849, carries a CVSS score of 9.3, and affects MLflow versions prior to 3.15.0.

The vulnerability is an unauthenticated server-side request forgery, or SSRF, weakness. An attacker capable of reaching a vulnerable MLflow tracking server can abuse model-registry webhooks to force the server to make requests to internal resources. That’s particularly dangerous in cloud environments because internal metadata services can contain credentials, tokens and secrets that aren’t normally reachable from the public internet.

Researchers reported indiscriminate scanning for exposed MLflow servers within hours of the vulnerability receiving its CVE assignment on August 17. More concerning, attackers aren’t simply identifying vulnerable systems—they’re reportedly attempting to retrieve credentials and secrets from known cloud metadata addresses.

The vulnerability also demonstrates the danger of incomplete remediation. According to the research discussed on the show, the attack can bypass an earlier fix because of how MLflow handles web redirects. That’s another reminder that installing a security update doesn’t automatically mean the underlying attack path is completely gone.

If MLflow exists anywhere in your environment, upgrade to 3.15.0 or later immediately. Then review the server as though this were a credential-exposure event. Examine logs for unexpected requests to internal metadata endpoints and rotate cloud credentials, API keys and secrets that could have been reachable from the tracking server.

If your MLflow server was exposed to the internet during the exploitation window, patching is step one.

Determining whether somebody got there before you is step two.

FUXA Industrial Automation Platform Draws Active Scanning

MLflow isn’t the only open-source platform receiving attacker attention. A separate critical vulnerability affecting FUXA, an open-source SCADA and industrial-automation platform, is also drawing active scanning.

The vulnerability carries a CVSS score of 9.5 and allows an unauthenticated attacker to write arbitrary files to a vulnerable server, potentially resulting in remote-code execution. Researchers identified broad scanning activity from a single source targeting the approximately 60 FUXA installations exposed directly to the internet. At the time of today’s episode, researchers had not confirmed deployment of a working exploit payload.

Sixty exposed systems may sound insignificant compared with vulnerabilities affecting millions of endpoints, but that’s exactly why this deserves immediate attention. Sixty targets are easy to enumerate, and industrial-control environments can carry consequences far beyond the compromised server itself.

If you’re operating FUXA inside an OT environment, determine whether it’s externally accessible.

And if it is, get it off the public internet today regardless of patch status.

Windows Vulnerability Now Confirmed in Ransomware Attacks

CISA has confirmed ransomware operators are exploiting a Windows privilege-escalation vulnerability that Microsoft patched in November 2025.

The vulnerability, CVE-2025-60710, affects Windows Task Host and involves a link-following weakness that allows a local attacker with basic permissions to elevate privileges and obtain SYSTEM-level control over vulnerable Windows 11 and Windows Server 2025 systems.

CISA hasn’t publicly disclosed the specific ransomware groups or technical attack chains associated with the vulnerability, and Microsoft’s advisory had not yet been updated to acknowledge exploitation at the time of today’s show. But CISA’s decision to specifically associate the vulnerability with ransomware changes how security teams should prioritize it.

The numbers provide useful context. Since November 2021, CISA has reportedly identified 383 actively exploited Microsoft vulnerabilities, with 112 eventually associated with ransomware operations.

This is now one of them.

If Windows 11 or Windows Server 2025 systems in your environment missed the November 2025 security update, move this vulnerability to the front of the remediation queue. More importantly, use your vulnerability-management platform to identify systems that have accumulated months of missing security updates.

Attackers don’t care that a vulnerability is nine months old.

If the system is still vulnerable, the exploit still works.

Medusa Ransomware Has Compromised More Than 500 Organizations

CISA, the FBI and HHS have updated their joint advisory on the Medusa ransomware operation, confirming the group has compromised more than 500 organizations across critical-infrastructure sectors, including healthcare, education, legal services, insurance, manufacturing and technology.

“Our emergency patching SLA can’t be measured in weeks anymore or even days.”

Medusa operates through a ransomware-as-a-service model where core developers provide the ransomware infrastructure and affiliates conduct attacks in exchange for a portion of extortion proceeds. Those affiliates typically obtain initial access through two routes: purchasing legitimate corporate credentials from initial-access brokers or exploiting known vulnerabilities in enterprise products.

The vulnerability list should sound familiar to most practitioners. It includes weaknesses affecting ScreenConnect, Fortinet FortiClient EMS, GoAnywhere MFT and BeyondTrust. Federal investigators warn that Medusa affiliates are capable of weaponizing publicly disclosed vulnerabilities within hours, sometimes before organizations have patches available.

Once inside, the attackers deliberately avoid immediately deploying noisy malware. They use legitimate Windows tools—including PowerShell, Command Prompt and Windows Management Instrumentation—to perform reconnaissance and lateral movement. They then deploy vulnerable or stolen kernel drivers to interfere with EDR products, dump credentials from memory and exfiltrate information using tools such as Rclone.

Victims reportedly receive approximately 48 hours to begin negotiations, with ransom demands reaching as high as $15 million and average payments around $260,000.

This is industrialized ransomware.

Credentials get purchased. Vulnerabilities get weaponized. Native administrative tools provide stealth. Security software gets disabled. Data gets stolen. Systems get encrypted. Then the extortion begins.

Why Medusa Should Change Your Emergency Patching Model

The number from this advisory that matters most to me isn’t 500.

It’s 24 hours.

If ransomware affiliates can move from public vulnerability disclosure to working exploitation in less than a day, a seven-day emergency patch SLA isn’t particularly emergency anymore.

I’m not saying every vulnerability should bypass change management. That’s operationally irresponsible. I’m saying security programs need a separate lane for vulnerabilities where several conditions converge: active exploitation, internet exposure, high-impact systems, available exploit code or credible intelligence showing adversaries are moving.

For those vulnerabilities, the objective should be disclosure to containment or remediation in hours.

Everything else can continue through the normal process.

Microsoft Copilot “Co-Snitch” Could Turn One Link Into a Data-Theft Chain

Researchers disclosed three vulnerabilities affecting Microsoft Copilot Personal that collectively form an attack chain dubbed Co-Snitch. The vulnerabilities could allow an attacker to weaponize access that users had legitimately granted Copilot to connected services, including email, calendars, cloud storage and previous chat history. Microsoft has shipped fixes, and researchers reported no evidence the flaws were exploited before remediation.

The core weakness involved an undocumented URL parameter that could cause Copilot to automatically execute an embedded prompt when a crafted page loaded. Once triggered, that prompt could query services the user had already authorized, encode the retrieved information and exfiltrate it through Copilot’s own web-fetching functionality.

That’s particularly interesting from a defensive perspective because the resulting network traffic could look like normal Copilot activity rather than traditional malware exfiltration.

Researchers also identified a persistence mechanism where malicious instructions embedded inside a web page could be written into Copilot’s memory. Those instructions could reportedly survive password changes and session revocations until manually removed.

This illustrates why AI assistants need to be treated differently from traditional productivity applications.

When an AI system can access your email, files, calendar and chat history on your behalf, that AI assistant effectively becomes a privileged identity.

Organizations need to govern it accordingly.

Apple Releases Another Major macOS and iOS Security Update

Apple released another substantial collection of macOS and iOS security updates addressing dozens of vulnerabilities, including numerous WebKit weaknesses and kernel issues capable of causing memory corruption, sandbox escape and cross-origin information disclosure.

Apple had not identified active exploitation of these vulnerabilities at the time of today’s episode. However, the volume of WebKit fixes alone makes this an update I wouldn’t leave sitting for several weeks.

I’ve already updated my Mac, iPhone and iPad.

For managed Apple fleets, get these updates deployed this week. There’s no reason to turn straightforward endpoint maintenance into unnecessary vulnerability debt.

UT San Antonio Contains Cyberattack at the Network Edge

The University of Texas at San Antonio, which serves approximately 40,000 students, took phone systems and other services offline after its IT team detected malicious activity over the weekend.

According to the university, the activity was contained at the network edge before attackers reached core systems, and the investigation had found no evidence that information was accessed or exfiltrated at the time of the episode. No threat actor had claimed responsibility.

This is what successful incident containment can look like.

Not every cyberattack needs to become a data breach.

Detection, segmentation and decisive containment can turn an attempted intrusion into an operational disruption rather than a catastrophic incident.

Berlin Government Ministries Forced Back to Phones, Text and Fax

Two Berlin state government ministries have remained disconnected from the city’s IT network following the discovery of a security breach. Local reporting suggests attackers may have exploited a vulnerability in a ministry system.

The isolation has forced employees to rely on phones, text messaging and fax for official communications, while some housing and education-benefit applications cannot currently be processed. Officials had not attributed the attack or confirmed whether information was stolen at the time of today’s episode.

The incident is another reminder that cyber resilience isn’t simply about restoring servers.

Organizations need to understand which business processes disappear when technology disappears and whether alternative operating procedures actually work.

Ukraine Investigates Cyberattack Against Asset Recovery Agency

Ukraine’s Asset Recovery and Management Agency, or ARMA, says it experienced a cyberattack while investigating what it believes could be a coordinated attempt to disrupt a competition involving the management of corporate assets seized from a sanctioned Russian billionaire.

The agency reported suspicious activity including unauthorized database access dating back to the spring but had not publicly attributed the latest attack. Russian state-linked actors had previously targeted ARMA personnel earlier this year.

Given the geopolitical context, attribution matters and shouldn’t be assumed without evidence. But the incident demonstrates again how cyber operations increasingly intersect with sanctions, financial enforcement and state economic interests.

OpenAI Tightens Model Testing After Last Month’s Escape Incident

OpenAI announced new internal safeguards for model testing following last month’s incident in which a model escaped its intended test environment and interacted with a package-installation utility.

The company says it is implementing stronger network isolation along with monitoring capable of detecting unauthorized model behavior within minutes. Its largest frontier reinforcement-learning run remains paused while those controls are validated, and a complete postmortem remains pending.

This is the right direction, but the postmortem will matter.

If AI systems are being tested specifically to determine whether they can circumvent controls, then the evaluation environment itself needs to be engineered under an assumption of hostile behavior.

Sandbox escape has to be treated as a security incident, regardless of whether the actor escaping the sandbox is human-written malware or an AI model.

Anthropic Develops Statistical Watermarking for Claude

Anthropic is detailing an approach for watermarking text generated by Claude without inserting hidden characters into the output.

Instead, the technique subtly influences the randomness behind word selection, creating a statistical pattern that a separate detector can analyze to estimate whether Claude was involved in producing the text.

Anthropic appropriately emphasizes that detection would represent a probability rather than definitive proof of authorship. Factual answers and code would also carry little or no useful watermark because those outputs provide less flexibility in word selection.

That’s an important distinction.

AI detection should never become “the detector says AI, therefore the person cheated.”

Probability isn’t proof.

DOJ Charges 17 Alleged Iranian Hackers in Massive Intellectual-Property Campaign

We finish today’s show with the Justice Department unsealing charges against 17 alleged members of Iran’s Mabna Institute, who prosecutors accuse of conducting an IRGC-linked cyber-espionage campaign targeting American universities, private companies and government agencies since 2013.

According to prosecutors, the campaign targeted 144 U.S. universities, 42 private companies and at least five federal and state government agencies, stealing more than 31 terabytes of academic research and intellectual property.

The campaign reportedly focused heavily on professors and researchers, using credential theft to obtain access to university systems and valuable research.

Thirty-one terabytes matters because this isn’t primarily about monetizing stolen identities.

It’s about stealing innovation.

Universities, research institutions and private companies spend billions of dollars and years developing intellectual property. A state-backed cyber operation can potentially acquire that work for a fraction of the cost by compromising the people who created it.

For research universities and companies handling sensitive R&D, cybersecurity is therefore not simply an IT issue.

It’s economic security.

Leave a comment

James Azar’s CISOs Take

My biggest takeaway from today’s show is that speed has become one of the defining characteristics of cyber risk. MLflow was being targeted within hours. Medusa affiliates are weaponizing vulnerabilities in less than 24 hours. A vulnerability Microsoft patched nine months ago is still producing ransomware victims because enough systems remain unpatched to make exploitation profitable. We need to stop measuring vulnerability-management success exclusively by whether teams met an arbitrary SLA and start measuring whether we eliminated exploitable attack paths before adversaries reached them. That requires accurate asset inventories, external exposure management, threat intelligence, emergency change procedures and the authority to move quickly when those signals align.

The second issue is the changing definition of privileged access. Copilot demonstrates this perfectly. An AI assistant connected to your email, calendar, cloud storage and chat history isn’t simply another application; it has become an identity operating with delegated authority. MLflow can sit adjacent to cloud credentials. CI/CD systems can hold production secrets. AI agents can interact with real-world systems. The architecture of trust is changing faster than most governance programs. Security leaders need to start identifying these systems according to what they can access and what they can do, rather than what product category the vendor puts on the box. Attackers are already thinking that way. We need to as well.

Action Items

  • Patch MLflow to version 3.15.0 or later immediately and prioritize any internet-accessible tracking servers.

  • Rotate cloud credentials and secrets reachable from exposed MLflow servers and investigate metadata-service access for evidence of compromise.

  • Remove FOXA installations from direct internet exposure and review OT segmentation around affected systems.

  • Patch CVE-2025-60710 across Windows 11 and Windows Server 2025 and prioritize systems missing the November 2025 update.

  • Cross-reference the Medusa advisory against ScreenConnect, FortiClient EMS, GoAnywhere MFT and BeyondTrust deployments and verify remediation status.

  • Create or test a sub-24-hour emergency remediation lane for actively exploited, externally exposed vulnerabilities.

  • Enforce phishing-resistant MFA and restrict remote-management tooling across critical infrastructure and high-value enterprise systems.

  • Validate immutable offline backups and recovery procedures before ransomware forces you to test them under pressure.

  • Audit applications connected to Microsoft Copilot and remove permissions that aren’t operationally necessary.

  • Treat AI assistants with delegated enterprise access as privileged identities and monitor their access patterns accordingly.

  • Deploy Apple’s latest macOS, iOS and iPadOS security updates this week rather than allowing routine endpoint vulnerability debt to accumulate.

  • Review network segmentation and containment procedures using the UT San Antonio incident as a tabletop scenario for stopping an attack before it reaches core systems.

  • Validate business continuity procedures for prolonged IT isolation, including how critical functions operate without normal collaboration and workflow platforms.

  • Apply hostile-environment security principles to AI testing infrastructure, including network isolation, behavioral monitoring and strict external-access controls.

  • Review research and intellectual-property environments for state-sponsored targeting, particularly universities, R&D teams and organizations handling sensitive engineering data.

Stay Cyber Safe.

Thanks for reading CISO Talk by James Azar! This post is public so feel free to share it.

Share

Discussion about this episode

User's avatar

Ready for more?