Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Organizations utilizing MLflow AI platforms and FUXA SCADA/HMI software
Incident: Active exploitation of CVE-2026-64849 and CVE-2026-25895 to steal credentials and target industrial servers.
Impact: Exfiltration of sensitive cloud credentials and potential full system compromise via remote code execution.
Attacker: Unidentified threat actors
Analysis: Attackers are leveraging a critical SSRF vulnerability in MLflow to bypass security fixes and extract sensitive cloud metadata and credentials. Concurrently, malicious scanning is targeting a path traversal flaw in FUXA SCADA software to achieve remote code execution. These campaigns highlight a growing trend of targeting the underlying infrastructure of AI and operational technology.
Recommendations: Update MLflow to version 3.15.0 or higher immediately to remediate the SSRF flaw.; Patch FUXA installations to a version beyond 1.2.9 to prevent unauthorized file writes.; Review cloud audit logs for suspicious requests to internal metadata endpoints.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source