CISA Sets Sept. 2 Deadline to Patch, Amid Active Exploitation. Attackers are exploiting a flaw in exposed MLflow servers to reach systems that are normally closed to the internet. The bug may reveal cloud credentials without requiring a login. CISA has not disclosed the victims, attackers or results of the intrusions.
First seen on govinfosecurity.com
Jump to article: www.govinfosecurity.com/mlflow-flaw-opens-path-to-cloud-credentials-theft-a-32626
![]()

