LOWVulnerability
Global
MLflow Flaw Opens a Path to Cloud Credentials Theft
·Source: Bank Info Security
Updated:
Executive Summary
CISA Sets Sept. 2 Deadline to Patch, Amid Active Exploitation Attackers are exploiting a flaw in exposed MLflow servers to reach systems that are normally closed to the internet. The bug may reveal cloud credentials without
Analysis
CISA Sets Sept. 2 Deadline to Patch, Amid Active Exploitation Attackers are exploiting a flaw in exposed MLflow servers to reach systems that are normally closed to the internet. The bug may reveal cloud credentials without requiring a login. CISA has not disclosed the victims, attackers or results of the intrusions.