Technology newsroom
π¨ Urgent Alert! Critical Vulnerabilities in MLflow and FUXA Exploited by Hackers to Steal Cloud Credentials
Urgent security alert for MLflow and FUXA users. Hackers are actively exploiting SSRF vulnerabilities to steal Cloud Credentials and attack industrial control systems. Administrators are advised to update patches immediately.
π Key Takeaways:
- Hackers are scanning for and actively exploiting critical vulnerabilities in the open-source AI platform MLflow and the factory SCADA software FUXA.
- An SSRF vulnerability in MLflow allows malicious actors to directly steal critical data like Cloud Credentials and Secrets.
- System administrators using both software should check and update security patches as soon as possible to prevent damage.
Urgent reports from cybersecurity firms watchTowr and VulnCheck indicate intense scanning and attempted exploitation targeting two critical security vulnerabilities affecting two popular open-source software: MLflow, a platform for AI tasks, and FUXA, SCADA/HMI software for industrial control systems (OT).
π― In-depth look at MLflow Vulnerability
For MLflow, the discovered vulnerability is Server-Side Request Forgery (SSRF), which is extremely dangerous. It allows an attacker to compel the server running MLflow to send requests to other systems that are normally only accessible internally. The primary goal of hackers is to use this vulnerability to steal credentials and secrets from cloud services such as AWS, Azure, or Google Cloud, which could lead to a complete takeover of cloud infrastructure.
π Risks in OT Systems with FUXA
Meanwhile, FUXA, software used in Operational Technology (OT) and industrial automation systems, is also being targeted. Successful attacks on SCADA/HMI systems can have more severe consequences than just data breaches, as they can lead to production line shutdowns or even physical damage to machinery and equipment.
π‘οΈ Recommendations for Administrators
Administrators currently using MLflow or FUXA should be aware of the risks and immediately check their systems. It is recommended to apply the latest security patches from the developers as soon as possible. If patches are not yet available, consider restricting direct internet access to these platforms and using a firewall to filter untrusted traffic.
π¬ Does your organization regularly check for vulnerabilities in the open-source software you use? Let's share prevention strategies.