Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

Executive Summary

Security researchers report that attackers are actively scanning for and exploiting a Server‑Side Request Forgery (SSRF) vulnerability in the open‑source MLflow AI platform. The flaw allows adversaries to access internal cloud metadata services and retrieve credentials and secrets. A separate, critical vulnerability in the open‑source SCADA/HMI software FUXA is also being targeted, enabling attackers to gain unauthorized access to operational‑technology environments. Both exploits demonstrate the growing threat of cloud‑credential theft via open‑source tooling.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-08-18T17:44:05+00:00 - Category: threat-intel

"He who fears being conquered is sure of defeat."

— Napoleon Bonaparte
Source: The Hacker News