
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Malicious actors are targeting open-source AI platform MLflow and web-based SCADA software FUXA with critical vulnerabilities.
CVE and advisory hub

Malicious actors are targeting open-source AI platform MLflow and web-based SCADA software FUXA with critical vulnerabilities.

Researchers at Anthropic and EPFL have shown that AI agents can spread self-propagating payloads, dubbed 'mind viruses,' through persistent system prompt files. While no wild infections have been confirmed, the study highlights vulnerabilities in agent networks and varying susceptibility across models.

Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software.

Kaspersky researchers have discovered new components in the Cavern command-and-control framework used by Iranian nation-state hackers, expanding its communication capabilities and allowing it to blend in with legitimate traffic.

A summary of the latest cybersecurity threats and vulnerabilities.

Two high-severity vulnerabilities have been discovered in popular WordPress plugins, Forminator Forms and User Profile Builder, allowing unauthenticated attackers to execute arbitrary code and gain administrative access to sites.

A security researcher has released a proof-of-concept exploit for a Microsoft zero-day vulnerability, claiming it can bypass a previously released patch and grant an attacker SYSTEM-level privileges.

A high-severity vulnerability in Cisco's Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild, allowing an unauthenticated attacker to trigger a denial-of-service (DoS) condition.

SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution.

Microsoft has released its monthly security updates, addressing 398 flaws, including a Windows driver zero-day under active attack.

Adobe releases updates to address multiple critical security vulnerabilities in ColdFusion, Commerce, and Campaign Classic, with some flaws having a CVSS score of 10.0.

Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability, CVE-2026-59310, is a directory-traversal vulnerability in the VMware vCenter server that can be exploited to execute arbitrary code.