<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ssrf on CuraSec</title><link>https://curasec.metacog.co.kr/tags/ssrf/</link><description>Recent content in Ssrf on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 26 Aug 2026 11:42:13 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/ssrf/index.xml" rel="self" type="application/rss+xml"/><item><title>SSRF bypass: IP addresses obfuscated as hostnames evade blocklists</title><link>https://curasec.metacog.co.kr/insights/2026-08-26-obfuscating-ip-addresses-as-hostnames-tue-aug-25th/</link><pubDate>Wed, 26 Aug 2026 11:42:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-26-obfuscating-ip-addresses-as-hostnames-tue-aug-25th/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Highlights that string-matching or IP blocklists for SSRF protection (e.g. blocking &amp;lsquo;169.254.169.254&amp;rsquo;) can be bypassed via hostname equivalents — review your SSRF defenses to ensure they resolve hostnames before comparing, not just match raw strings.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Useful context for tuning SSRF-related detections: logs showing hostname variants of link-local or metadata addresses in outbound requests may indicate bypass attempts worth adding to hunt queries.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials</title><link>https://curasec.metacog.co.kr/insights/2026-08-19-attackers-exploit-mlflow-ssrf-flaw-to-steal-cloud-credential/</link><pubDate>Wed, 19 Aug 2026 11:36:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-19-attackers-exploit-mlflow-ssrf-flaw-to-steal-cloud-credential/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> MLflow is common in cloud-hosted ML pipelines and the SSRF flaw enables IMDS credential theft — active exploitation corroborated by two independent sources (watchTowr, VulnCheck). Patch MLflow to the fixed version immediately and audit IMDS endpoint access controls on any host running it.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation of MLflow SSRF is confirmed by two independent sources, with cloud credential theft as the objective. Hunt for anomalous outbound requests to IMDS (169.254.169.254) originating from ML pipeline hosts, and check for SSRF-pattern HTTP requests against MLflow endpoints since early August.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If your org runs MLflow in cloud environments, active exploitation of this SSRF flaw creates cloud credential-theft risk for data science or AI teams. Confirm engineering has inventoried and patched MLflow deployments this sprint and review whether any cloud credentials may have been exposed.&lt;/li>
&lt;/ul></description></item></channel></rss>