
Attackers are exploiting an MLflow SSRF flaw to reach cloud metadata services and steal credentials, while a separate FUXA issue is also drawing malicious traffic against exposed systems.
Once cloud metadata or exposed OT-adjacent tooling enters the picture, this stops being a niche software story and becomes an exposure and credential-containment problem.
What Changed
The immediate concern in the MLflow case is not just the bug itself. It is what an attacker can reach from that host once SSRF opens a path into cloud metadata or other internal-only services.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
Free. Weekday mornings. Unsubscribe anytime.
Built from 100+ trusted cybersecurity sources.
FUXA matters for a different reason: it is another reminder that specialized platforms can stay internet-reachable and lightly monitored long after they drop out of the routine patch conversation.
Why CyberExperts Flagged It
These are the kinds of issues that get underestimated because they sit outside the loudest enterprise product categories.
An exposed MLflow instance can turn into a fast cloud-credential theft path, and the FUXA activity shows how easily secondary platforms can become real attack surface if nobody owns the review cycle tightly.
What Defenders May Be Underestimating
Teams may underestimate how often the real damage comes from what the vulnerable platform can reach next, not from the first bug itself.
If MLflow can query metadata services or hold privileged cloud access, an attacker does not need much time to turn a web exposure problem into a credential and lateral-movement problem.
What Teams Should Do Next
- Check whether MLflow or FUXA is internet-exposed and restrict access immediately where that exposure is unnecessary.
- Block or tightly limit metadata-service reachability from systems that should not need it, especially externally reachable ML workloads.
- Rotate any credentials that may have been reachable from exposed hosts and review logs for suspicious requests against metadata or adjacent internal endpoints.
Source Context
CyberExperts is using The Hacker News as the primary reference for this update.
Related In The Daily Brief
See this item in The 5-Minute Cyber Brief