Full Archive · Page 13

Research archive, page 13

Browse entries 289–312 of 1346. Return to the first page to search and filter the complete collection.

The Hacker News AI Security August 18, 2026 news

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

CVE-2026-64849 is an unauthenticated SSRF flaw in MLflow model-registry webhooks that lets anyone reaching a vulnerable Tracking Server proxy requests to internal services and cloud metadata endpoints. The redirect handling bypasses earlier fixes, and honeypot telemetry showed indiscriminate scanning within hours of disclosure aimed at stealing cloud credentials and secrets. MLflow fixed the issue in 3.15.0.