Breaking
Democrats call for USS Lincoln probe, question US Navy’s readinessOut of Ammo: A Two-Year Sprint to Rebuild the American Arsenal and Deter ChinaGlobal Debt Crises Foreshadow a Perilous Path for the United StatesMalaysia CISOs urged to hunt MacSync Stealer via behavioral pivotsChargEV offers RM10 voucher to referee, 50% discount to referrerApple’s next AirPods to include built-in cameras for Visual IntelligenceMeta referred to court, accused of concealing platform risks to teensBritish newlyweds die in Greece helicopter crash on honeymoonPhilippines open to scrapping some taxes to ease consumer burdenFrom data to policy: Building Africa’s evidence ecosystem for better tax reformIMF pushes for beneficial ownership transparency in new AML guidanceFBM KLCI ends three-day losing streak as banking shares reboundHong Kong’s 5-year plan consultation has sparked valuable discussionsClop builds custom web shell for Windchill servers in data theft campaignTop Chef turns to tears as host Kristen Kish redefines the roleMicrosoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected AppsMLflow flaw exploited to steal cloud credentialsESMA consults on reporting framework for clearing activity at recognised third-country CCPsECB collateral surprises cut bank risk and narrow bond spreadsFlores power restored after earthquake as all 1.144m customers back onlineDemocrats call for USS Lincoln probe, question US Navy’s readinessOut of Ammo: A Two-Year Sprint to Rebuild the American Arsenal and Deter ChinaGlobal Debt Crises Foreshadow a Perilous Path for the United StatesMalaysia CISOs urged to hunt MacSync Stealer via behavioral pivotsChargEV offers RM10 voucher to referee, 50% discount to referrerApple’s next AirPods to include built-in cameras for Visual IntelligenceMeta referred to court, accused of concealing platform risks to teensBritish newlyweds die in Greece helicopter crash on honeymoonPhilippines open to scrapping some taxes to ease consumer burdenFrom data to policy: Building Africa’s evidence ecosystem for better tax reformIMF pushes for beneficial ownership transparency in new AML guidanceFBM KLCI ends three-day losing streak as banking shares reboundHong Kong’s 5-year plan consultation has sparked valuable discussionsClop builds custom web shell for Windchill servers in data theft campaignTop Chef turns to tears as host Kristen Kish redefines the roleMicrosoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected AppsMLflow flaw exploited to steal cloud credentialsESMA consults on reporting framework for clearing activity at recognised third-country CCPsECB collateral surprises cut bank risk and narrow bond spreadsFlores power restored after earthquake as all 1.144m customers back online
Economy

MLflow flaw exploited to steal cloud credentials

Attackers are exploiting a new server-side request forgery (SSRF) flaw in MLflow to steal cloud metadata and secrets, watchTowr reported on August 17, 2026.

Source: The Hacker News · August 18, 2026 at 11:01 PM · AI-assisted report

Single-source
MLflow flaw exploited to steal cloud credentials
Photo: Gwydion M. Williams via flickr (BY)

KUALA LUMPUR, 19 AUGUST 2026 —

Listen to this article

DomainFork Audio · read aloud

Attackers are exploiting a new server-side request forgery (SSRF) flaw in MLflow to steal cloud metadata and secrets, watchTowr reported on August 17, 2026.

Market Impact

The flaw, tracked as CVE-2026-64849, lets an attacker proxy requests through exposed MLflow instances and reach internal cloud services, according to watchTowr principal threat intelligence specialist Yordan Ganchev. The cybersecurity firm detected indiscriminate scanning for exposed MLflow systems within hours of the CVE being assigned. Evidence from global honeypot telemetry shows attackers targeting cloud-hosted MLflow deployments to extract credentials from well-known internal IP addresses and services.

Ganchev said the bug bypasses prior fixes because of how it handles web redirects.

Affected organizations should patch exposed systems, review audit logs for signs of compromise, and check whether sensitive credentials have been exposed.

Separately, attackers are scanning for a path traversal flaw, CVE-2026-25895, in FUXA, an open-source SCADA/HMI platform. VulnCheck vice president of research Caitlin Condon said a single IP address has been broadly scanning the internet for vulnerable FUXA instances since August 18, 2026. About 60 FUXA installations are exposed to the public internet. Condon said attackers are attempting to overwrite main.js via the path traversal flaw, but no remote code execution payloads have been observed.

FUXA has seen two other vulnerabilities—CVE-2026-25939 and CVE-2023-33831—actively exploited in the past year, with the latter targeted as recently as the day before.

Reporting based on The Hacker News. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.