Full Archive · Page 22

Research archive, page 22

Browse entries 505–528 of 1531. Return to the first page to search and filter the complete collection.

The Hacker News AI Security August 18, 2026 news

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

CVE-2026-64849 is an unauthenticated SSRF flaw in MLflow model-registry webhooks that lets anyone reaching a vulnerable Tracking Server proxy requests to internal services and cloud metadata endpoints. The redirect handling bypasses earlier fixes, and honeypot telemetry showed indiscriminate scanning within hours of disclosure aimed at stealing cloud credentials and secrets. MLflow fixed the issue in 3.15.0.