⤷ Title: The CVE Watchtower: Weekly Threat Intelligence Briefing (March 30 – April 5, 2026)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 00:57:54 +0000
════════════════════════
⌗ Tags: #Weekly Recap #AI security #Chrome Dawn #CISA KEV #CVE_2026_35616 #CVE_2026_5281 #cyber risk #infosec #MLflow #NetScaler #patch management #Vulnerability Digest
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 00:57:54 +0000
════════════════════════
⌗ Tags: #Weekly Recap #AI security #Chrome Dawn #CISA KEV #CVE_2026_35616 #CVE_2026_5281 #cyber risk #infosec #MLflow #NetScaler #patch management #Vulnerability Digest
Daily CyberSecurity
The CVE Watchtower: Weekly Threat Intelligence Briefing (March 30 – April 5, 2026)
1,361 vulnerabilities found this week: 129 are critical. Prioritize Chrome’s Dawn exploit, FortiClient EMS, and new AI pipeline attacks. Get the full list.
⤷ Title: Thousands of Publicly Exposed MLflow Instances — A Hidden Risk in MLOps Infrastructure
════════════════════════
𐀪 Author: Dehacker
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:31:09 GMT
════════════════════════
⌗ Tags: #ai_security #bug_bounty #mlflow #security #mlops
════════════════════════
𐀪 Author: Dehacker
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:31:09 GMT
════════════════════════
⌗ Tags: #ai_security #bug_bounty #mlflow #security #mlops
Medium
Thousands of Publicly Exposed MLflow Instances — A Hidden Risk in MLOps Infrastructure
Summary
⤷ Title: Thousands of Publicly Exposed MLflow Instances — A Hidden Risk in MLOps Infrastructure
════════════════════════
𐀪 Author: d3hack3r
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:31:09 GMT
════════════════════════
⌗ Tags: #ai_security #bug_bounty #mlflow #security #mlops
════════════════════════
𐀪 Author: d3hack3r
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:31:09 GMT
════════════════════════
⌗ Tags: #ai_security #bug_bounty #mlflow #security #mlops
Medium
Thousands of Publicly Exposed MLflow Instances — A Hidden Risk in MLOps Infrastructure
Summary
⤷ Title: PoC Discloses for CVE-2026-64849: watchTowr Sees Attacks on MLflow SSRF
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 12:32:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #CVE_2026_64849 #MLflow #MLflow vulnerability #proof_of_concept exploit #ssrf #watchTowr
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 12:32:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #CVE_2026_64849 #MLflow #MLflow vulnerability #proof_of_concept exploit #ssrf #watchTowr
Daily CyberSecurity
PoC Discloses for CVE-2026-64849: watchTowr Sees Attacks on MLflow SSRF
TL;DR A default MLflow tracking server can be turned into a proxy for reading internal services. Tracked as CVE-2026-64849, the flaw is an unauthenticated full-read SSRF in MLflow’s webhook …