CyberSecurity News
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
AI summary
Attackers are exploiting vulnerabilities in MLflow and FUXA to steal sensitive information. The flaws in MLflow, an open-source AI platform, and FUXA, a web-based SCADA/HMI software, are being targeted by malicious actors. Specifically, a vulnerability in MLflow is being used to exploit a server-side request forgery flaw. Reports from watchTowr and VulnCheck have identified these vulnerabilities as being actively scanned and exploited. The exploitation of the MLflow vulnerability allows attackers to steal cloud credentials and secrets.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

