A critical unauthenticated SSRF in MLflow's webhook delivery lets attackers pivot into cloud metadata endpoints and steal credentials. WatchTowr's honeypot network caught scanning starting within hours of the CVE going public.
A critical unauthenticated SSRF in MLflow's webhook delivery lets attackers pivot into cloud metadata endpoints and steal credentials. WatchTowr's honeypot network caught scanning starting within hours of the CVE going public.
University of Toronto researchers presented GPUBreach at Black Hat 2026 — a Rowhammer attack that escalates from an unprivileged CUDA kernel to a host root shell, bypassing IOMMU, threatening shared AI cloud GPU infrastructure.
A server-side request forgery vulnerability in LMDeploy's vision-language image loader let attackers reach cloud instance metadata services and harvest full credentials. The first confirmed exploitation hit Sysdig's honeypot less than 13 hours after the CVE dropped.
Sygnia's investigation into a financially motivated cloud breach found a lone threat actor compressed what typically takes multiple operators weeks into 72 hours -- using AI-assisted tooling to chain credential theft, lateral movement, and extortion-ready disruption at a pace no human could sustain alone.
Orca Security's 2026 State of AI Security Report finds that nearly all AI vulnerability alerts with available patches are ignored, while 74% of companies carry at least one critical CVE in their AI stack.