CuraSec

tag: Cloud-Credentials · 2 items

2026-08-19 · The Hacker News · source ↗ #mlflow#ssrf#cloud-credentials
  • Engineer — Act: MLflow is common in cloud-hosted ML pipelines and the SSRF flaw enables IMDS credential theft — active exploitation corroborated by two independent sources (watchTowr, VulnCheck). Patch MLflow to the fixed version immediately and audit IMDS endpoint access controls on any host running it.
  • SOC/IR — Act: Active exploitation of MLflow SSRF is confirmed by two independent sources, with cloud credential theft as the objective. Hunt for anomalous outbound requests to IMDS (169.254.169.254) originating from ML pipeline hosts, and check for SSRF-pattern HTTP requests against MLflow endpoints since early August.
  • Leader — Plan: If your org runs MLflow in cloud environments, active exploitation of this SSRF flaw creates cloud credential-theft risk for data science or AI teams. Confirm engineering has inventoried and patched MLflow deployments this sprint and review whether any cloud credentials may have been exposed.
  • Engineer — Act: Actively scanning for internet-exposed instances of ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio to harvest AWS keys and Kubernetes tokens — exactly the stack teams deploy fast without firewall controls. Audit now for public exposure of these service ports, restrict to internal networks, and rotate AWS/K8s credentials on any host that ran them exposed.
  • SOC/IR — Plan: The TTPs are concrete enough to build detections around: Shodan-driven scanning targeting AI service endpoints, followed by credential exfiltration. Build hunts for unusual outbound traffic or credential API calls originating from AI service hosts; the summary appears truncated so IOCs are not yet available to act on directly.
  • Leader — Plan: A claimed harvest of 3,811 AWS keys illustrates the systemic risk of teams rapidly standing up AI infrastructure without security review. Raise with engineering and DevSecOps leadership to establish a deployment standard for AI tooling that includes network isolation requirements before services go live.