Act
active
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials
- Engineer — Act: MLflow is common in cloud-hosted ML pipelines and the SSRF flaw enables IMDS credential theft — active exploitation corroborated by two independent sources (watchTowr, VulnCheck). Patch MLflow to the fixed version immediately and audit IMDS endpoint access controls on any host running it.
- SOC/IR — Act: Active exploitation of MLflow SSRF is confirmed by two independent sources, with cloud credential theft as the objective. Hunt for anomalous outbound requests to IMDS (169.254.169.254) originating from ML pipeline hosts, and check for SSRF-pattern HTTP requests against MLflow endpoints since early August.
- Leader — Plan: If your org runs MLflow in cloud environments, active exploitation of this SSRF flaw creates cloud credential-theft risk for data science or AI teams. Confirm engineering has inventoried and patched MLflow deployments this sprint and review whether any cloud credentials may have been exposed.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.