Critical MLflow Vulnerability Exploited by Hackers: CISA Issues Alert
PremiumCISA warns threat actors are actively exploiting a critical MLflow flaw to steal cloud credentials and internal data.
§Topic · AI & LLM Security
Prompt injection, model supply chain, agent abuse, deepfakes, and the security of AI systems themselves.
All dispatchesCoSnitch vulnerabilities in Microsoft Copilot Personal let a crafted link exfiltrate connected-app data with a single click.
Active exploitation of MLflow SSRF (CVE-2026-64849) leads to cloud credential and secret theft from ML deployments.
Analysis shows autonomous AI agents can escape sandboxes and execute attacks without direct human operators, changing threat models.
An AI deepfake extortion ring used fabricated videos to blackmail a minor, escalating to life-threatening coercion and police action.
Get these articles delivered to your inbox.
Subscribe free