August 21, 2026
- CISA has now formally warned federal agencies about the MLflow SSRF flaw, which attackers are using to reach internal endpoints and steal cloud credentials and secrets from AI/ML infrastructure (BleepingComputer, SecurityWeek) (earlier coverage). · Exploited in the Wild