← Back to blog

MLflow SSRF Vulnerability Actively Exploited to Steal Cloud Secrets

Attackers are exploiting a critical SSRF flaw in MLflow to access cloud credentials. Similar vulnerabilities are being targeted in FUXA, an industrial automation platform.

TL;DR

  • Critical SSRF vulnerability in MLflow is under active exploitation.
  • Attackers are stealing cloud credentials and secrets from unpatched instances.
  • Similar flaws found in FUXA, an OT/industrial automation tool, are also being scanned.
  • Organizations using these tools should patch immediately.
  • Security teams should monitor for unauthorized cloud API access.

Threat actors are actively scanning and exploiting critical vulnerabilities in popular open-source platforms used for AI development and industrial automation. A severe server-side request forgery (SSRF) flaw in MLflow, a widely adopted machine learning lifecycle management tool, is being leveraged to steal cloud credentials and access sensitive internal resources.

Independent security researchers from watchTowr and VulnCheck have confirmed that attackers are chaining this vulnerability with others in FUXA, an open-source supervisory control and data acquisition (SCADA) system used in operational technology environments. These discoveries highlight growing risks at the intersection of AI infrastructure and industrial systems.

Organizations running unpatched versions of either platform are at immediate risk of credential theft, lateral movement, and potential compromise of connected cloud services and industrial networks.

MLflow SSRF Flaw Enables Credential Theft

  • The SSRF vulnerability allows attackers to force the MLflow server to make unintended requests to internal services.
  • Exploitation can lead to retrieval of cloud metadata, including temporary credentials stored in instance metadata services.
  • Attackers are using this method to gain persistent access to cloud environments without needing direct authentication.
  • The flaw affects MLflow instances exposed to untrusted networks or the public internet.
  • watchTowr Labs reported successful exploitation leading to full cloud account takeover in some cases.

Industrial Tool FUXA Also Under Attack

  • FUXA, used for human-machine interface (HMI) functions in industrial settings, contains related vulnerabilities.
  • Security scans targeting both MLflow and FUXA endpoints suggest coordinated reconnaissance campaigns.
  • These systems often reside in less-monitored network segments, increasing exploitation risk.
  • Compromise of FUXA could allow attackers to manipulate industrial processes or extract operational data.
  • VulnCheck has published detection signatures to help defenders identify vulnerable installations.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

MLflow SSRF Vulnerability Actively Exploited to Steal Cloud Secrets — Agent Breach Blog | Agent Breach