$ techbeacon
CVE & Exploits

Active Exploits Target MLflow and FUXA Platforms, Threatening Cloud Secrets and Industrial Controls

Active Exploits Target MLflow and FUXA Platforms, Threatening Cloud Secrets and Industrial Controls

Security researchers have observed active exploitation and scanning campaigns targeting critical vulnerabilities in two widely used open-source platforms: MLflow, a popular framework for managing artificial intelligence (AI) lifecycles, and FUXA, a web-based SCADA/HMI system designed for industrial automation. The activity represents a growing trend of threat actors aiming at both cutting-edge AI development environments and sensitive operational technology (OT) systems.

In the case of MLflow, attackers are actively leveraging a Server-Side Request Forgery (SSRF) vulnerability. This security loophole allows unauthorized parties to manipulate the platform into making arbitrary network requests. By exploiting this flaw, malicious actors can bypass perimeter defenses and query internal resources, such as cloud metadata services. This unauthorized access is then used to extract highly sensitive cloud credentials and proprietary secrets, potentially exposing entire corporate cloud infrastructures to deeper compromise.

MLflow is an essential framework used by data scientists and developers to track experiments, package code, and deploy machine learning models. Because these workflows often require deep integration with cloud storage and compute resources, the platform typically holds extensive permissions. Compromising an MLflow instance can give attackers a direct pipeline into an organization's proprietary datasets, training pipelines, and production environments, making it an incredibly high-value target.

Simultaneously, threat actors are scanning for and attempting to exploit a critical flaw in FUXA. As an open-source, web-based supervisory control and data acquisition (SCADA) and human-machine interface (HMI) application, FUXA is deployed within operational technology environments to monitor and control industrial automation processes. Vulnerabilities in such software are particularly dangerous, as successful exploitation can allow remote actors to gain unauthorized access to physical control systems, potentially disrupting manufacturing, utilities, or logistics operations.

The dual campaigns, which were initially highlighted in reports by The Hacker News, underscore a shifting threat landscape where attackers are diversifying their targets. Rather than focusing solely on traditional enterprise IT software, cybercriminals are increasingly auditing specialized open-source tools. The rapid adoption of AI technologies has outpaced security implementations in some sectors, while legacy industrial systems moving toward web-based interfaces face unique exposure risks when connected to external networks.

Organizations utilizing either MLflow or FUXA are urged to review their deployments immediately. Security experts recommend ensuring all instances are updated to the latest patched versions and restricting access to these interfaces behind virtual private networks (VPNs) or robust access-control lists. Additionally, limiting the permissions of service accounts associated with AI platforms can significantly mitigate the blast radius should an SSRF or similar vulnerability be exploited.

Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related