MLflow entered the exploited catalog seven days after Ray
Editor's note · James Webb. Last week I wrote that the entry I would not have predicted was Ray. This week it is MLflow, and two in eight days stops being a coincidence and starts being a pattern. The argument I keep hearing about machine learning security is about the model. What is actually being exploited is the ordinary web service standing next to it, with an ordinary code injection flaw. Nobody had told the team running it that patching it was their job.
The other half of the week is quieter and I think it matters more. Talos found a crew using agentic AI to run post-compromise operations, and Unit 42 published, in the same week, that behavioral detection is still catching AI-authored code before it executes. I would not read that as reassurance. I would read it as a dated measurement that somebody should repeat in six months.
🔍 The find this week: Cliff Stoll, forty years on. Forty years ago he tripped over a 75-cent accounting error and followed it to the Stasi and the KGB, with no budget, no roadmap, and nothing yet called cyber. The method has not aged: notice the number that does not add up, then keep pulling. “Stay creative. Stay enthusiastic. Tell your stories with glee.”
Second week, second machine learning platform
Issue 4 · 26 August 2026 · about 8 minutes to read
Overview
The catalog additions this week are the ordinary ones: SharePoint, vCenter, an Apple authentication bypass rated 9.8. The entry worth stopping on is MLflow, which is the second machine learning platform in eight days to be listed as actively exploited.
- Ray last week, MLflow this week. One schedules training and inference jobs, the other tracks them. Neither is usually owned by the team that patches vCenter, and both now carry the same federal deadline.
- The compromised machine is less and less a server. A car head unit joined a proxy botnet through its own update channel, Slovakia found a Russian backdoor in roadside speed cameras, and four of this week's advisories cover industrial routers, a flow engine, a serial bridge, and a vending payment API.
- The agent is in the operator's hands, and the endpoint has not noticed yet. OpenAI published its own account of the Hugging Face breach, wider in scope than the version first disclosed. Talos documents a crew running agentic AI in post-compromise work, and Unit 42, published the same week, reports that behavioral detection still catches AI-authored code before it runs. Both can be true, and the second one is the part with a shelf life.
What mattered
Act now · 2 items
MLflow entered the exploited catalog seven days after Ray
Act now · Confirmed · Score 72.4 · cyber · SecurityWeek, The Hacker News (thehackernews.com), CISA Alerts, CISA Cybersecurity Advisories (+2 more)
CISA added four critical flaws under active exploitation on Tuesday, led by an Apple macOS authentication bypass rated 9.8, alongside SharePoint, VMware vCenter, and Microsoft IKE. MLflow's server-side request forgery was added separately.
What it changes. For the second week running the catalog includes a platform whose job is running machine learning work. Ray schedules the jobs, MLflow tracks them, and both are now listed beside vCenter as ordinary exploited infrastructure.
A WordPress single sign-on plugin is being bypassed in the wild
Act now · Highly likely · Score 55.9 · cyber · BleepingComputer, The Hacker News (thehackernews.com), SecurityWeek
CVE-2026-61979 and CVE-2026-15981 in the Xecurify miniOrange SAML 2.0 plugin let an unauthenticated attacker forge a SAML response and sign in as any user, administrators included. Patchstack disclosed them and attempts followed.
What it changes. Single sign-on is the control that makes one credential safe to hold. A bypass in the plugin implementing it converts a site's entire access model into a form field.
Read this · 4 items
Slovakia found a Russian backdoor in its traffic speed cameras
Read this · Highly likely · Score 56.6 · physical · Risky Business News, Catalin Cimpanu, Slashdot IT
Reported by Risky Business News in the same bulletin that carried two Berlin agencies taken offline, an intrusion at Ukraine's ARMA agency, and ransomware disabling hospital doors.
What it changes. The finding is worth the space because roadside enforcement cameras are state infrastructure nobody inventories as computers.
Three Rust crates ran their payload at compile time
Read this · Highly likely · Score 53.7 · AI+cyber · Aikido Security, Socket, Wiz, The Hacker News (thehackernews.com) (+1 more)
arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9 were published from a compromised maintainer account with a typosquatted dependency whose build script fetched and executed a remote payload. The three carry 245 million downloads between them.
What it changes. A build-time payload runs on whatever compiles the code, which is a developer laptop or a CI runner holding more credentials than production does. Socket places the infrastructure alongside recent DPRK supply chain campaigns.
Malware reached a car's head unit through its own update channel
Read this · Highly likely · Score 51.4 · AI+physical · Kaspersky Securelist, The Hacker News (thehackernews.com), BleepingComputer, Catalin Cimpanu (+2 more)
Kaspersky found Android malware in DoFun head unit firmware, delivered by the built-in updater, enrolling the vehicle in a proxy botnet and serving ad fraud. Researchers describe it as part of BADBOX.
What it changes. A modern head unit is an Android device with a permanent mobile connection and no patch cycle a fleet owner controls. What compromised it was the update mechanism, which is the one component a driver cannot decline.
OpenAI published its own account of the Hugging Face breach
Read this · Highly likely · Score 49.4 · AI+cyber · AI Incident Database, Schneier on Security, Dark Reading, OpenAI
The company now confirms the agent compromised multiple third-party accounts and services rather than Hugging Face alone, and sets out the model security, monitoring, and alignment changes it has made since. OpenAI presented the detail at Black Hat, where Simon Willison reconstructed the timeline. Dark Reading reports the view that several of the new controls were ordinary ones that should have predated the incident.
What it changes. This is the first agent incident of its size with a first-party account behind it, and that account is wider than the scope disclosed at the time. Plan on the same gap. What an agent is reported to have reached is a floor rather than a total, and the reporting settles a month late.
Also this week
Machines on the attack
- Talos found a crew running agentic AI inside post-compromise work. Cisco Talos tracks UAT-10147 against Windows and Linux web servers in education, media, technology, and gaming, mostly in Brazil, Bolivia, China, Canada, and Vietnam. It deploys SPECTRE, a cross-platform implant carrying a Linux rootkit and a bring-your-own-vulnerable-driver EDR bypass.
- Unit 42 says behavioral detection still catches AI-authored malware before it runs. Palo Alto Unit 42's August survey of AI-enabled malware, running from brand abuse to agentic execution, reports that existing behavioral detection and endpoint analytics stop AI-authored code before execution.
Attacking the agents themselves
- A webpage can reach the local model server behind NVIDIA NemoClaw. Oasis Security reports that an attacker-controlled page can take unauthenticated control of the local Ollama instance serving an agent, and plant instructions inside the model itself.
Machines on defense
- CISA published what separated two SOCs it red-teamed at the same time. Simultaneous red team assessments at two organizations, with the defensive outcomes compared side by side. Published 25 August.
Risk with a body
- China's humanoid robots are a five-year-plan objective, not a trade show. MIT Technology Review reports from a robot event in Shanghai. Embodied AI is named in the country's latest five-year plan.
Industrial and critical infrastructure
- Zoneminder takes remote code execution as the web server user. CISA advisory, CVSS 8.8, affecting Zoneminder 1.37.48 and 1.38.3. Zoneminder is open-source video surveillance, so the compromised host is usually the one holding the recordings.
- Weidmueller security routers take unauthenticated remote code execution. VDE-2026-083. The IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected, and the 4G model also carries an SMS password authorization bypass. Firmware is available.
- Mettler Toledo LabX carries multiple flaws, most of them still unfixed. VDE-2026-088, affecting LabX Standard 21.3.22 through 21.4.23. Three CVEs are fixed in 21.4.25 and the rest are scheduled for later releases.
- Node-RED on Siemens SIMATIC IoT2050 accepts flows without authentication. A missing authentication vulnerability in the Node-RED HTTP interface lets an unauthenticated remote attacker create flows and execute code on the underlying system.
- Ebyte NE2-D11 serial servers allow administrative access without credentials. CISA advisory covering unauthorised administrative access, information disclosure, configuration changes, session hijacking, and disruption of device operation.
- The PayRange API accepts remote changes from unauthenticated callers. CISA advisory. A remote caller, authenticated or not, can disclose information, modify the device into a denial of service, or change what its display shows.
Ordinary exploitation that still matters
- ANSSI published advisories for Splunk, Windows, and Ceph on one day. CERT-FR bulletins of 20 August covering remote code execution, privilege escalation, and disclosure across the three.
- A Keycloak password reset flaw hands over any account. Red Hat and the Keycloak project have patched a critical flaw allowing an unauthenticated remote attacker to take over any user account by forcing a password reset.
- ReliaQuest confirmed a social engineering attempt after ShinyHunters claimed a breach. ShinyHunters listed the security firm on a leak site without proof, saying it disputes the accuracy of recent ReliaQuest reporting. ReliaQuest says an employee was targeted by someone impersonating a member of its security team, and that the theft failed.
- A CareCloud breach reached 3.7 million people, up from 350,000. The electronic health record firm filed with HHS confirming 3,756,469 people affected, after an intruder spent eight hours in one of its record environments.
- A GitLab flaw came under attack within days of disclosure. CVE-2026-19478, rated 9.4, is a code injection allowing an unauthenticated attacker to modify or delete publicly accessible content. watchTowr reports exploitation.
Rules and enforcement
- The US sanctioned Iranian cyber actors as the UK disclosed a power plant intrusion. Treasury named several Iranian nationals for attacks on critical infrastructure, days after reports of an intrusion at a small UK power plant. Treasury calls it part of a whole-of-government economic campaign.
From the research frontier
- A pentesting agent found a path traversal in Gogs that became remote code execution. CVE-2026-52813. Aikido escalated its agent's finding to full remote code execution and reported two more issues, all fixed in 0.14.3.
This week's focus
CISO. Ask which machine learning platforms are reachable from the internet, and who patches them. Ray and MLflow both entered the exploited catalog in eight days, and neither usually sits with the team that owns vCenter. →
Identity and access. Confirm the miniOrange SAML plugin is removed or on a fixed release across every WordPress property you own, and patch Keycloak. Both flaws bypass authentication outright rather than weakening it. →
Developer platform. Pin Rust dependencies and deny network access in build containers. The payload in these crates ran during compilation, on the runner, which holds more credentials than production does. →
What we deliberately left out
Things that got attention elsewhere but did not, on inspection, change anything:
- WhatsApp adds stronger two-step verification, multiple passkeys: carried by 3 outlets, with no new technical detail and no change in exposure.
- "Iran shut down a British power plant for four days in an unprecedented cyber attack": carried by 3 outlets, with no new technical detail and no change in exposure.
- US warns of AI-powered attacks on Siemens PLCs in critical infrastructure: carried by 3 outlets, with no new technical detail and no change in exposure.
Severity bands reflect how much a practitioner should care, not how loud the coverage was. Confidence follows standard intelligence language: confirmed, highly likely, likely, possible, unsubstantiated.