Exploitation of MLflow SSRF Vulnerability Leads to Cloud Credential Theft

Recent reports indicate that attackers are actively exploiting a critical SSRF vulnerability in MLflow, an open-source AI platform, to extract sensitive cloud credentials.

Recent reports indicate that attackers are actively exploiting a critical SSRF vulnerability in MLflow, an open-source AI platform, to extract sensitive cloud credentials.

Recent findings reveal vulnerabilities in Microsoft Copilot Personal that could allow unauthorized data access through a single click.

A newly disclosed vulnerability in Microsoft SharePoint, identified as CVE-2026-55040, is being actively exploited following the release of proof-of-concept code. This critical flaw allows attackers to bypass authentication and impersonate users.

A recently identified vulnerability in Atlassian's Rovo assistant allows attackers to extract data from Jira and Confluence. While one exploit path has been confirmed closed, the status of another remains uncertain.

A recently disclosed vulnerability in the Linux kernel, known as Zapscape, could enable attackers to escape KVM isolation and execute code on the host system from a guest virtual machine.

A serious vulnerability in IBM's Langflow AI platform allows unauthorized remote code execution, prompting urgent action for affected users.

A recent discovery by Pillar Security highlights a significant vulnerability in Google's Agent Development Kit, enabling potential agent-on-agent exploitation.

A significant flaw in Coldcard hardware wallets has been identified as the cause behind the theft of over $70 million in Bitcoin. The vulnerability stems from a firmware issue that affects the generation of cryptographic seeds.

A recent analysis reveals vulnerabilities in Microsoft Word's Copilot feature, allowing for self-propagating attacks through document workflows.

A public exploit has been released for a previously patched remote code execution vulnerability in vBulletin, affecting versions 6.2.1 and earlier, as well as 6.1.6 and earlier.