4 min read
News Brief A critical unauthenticated SSRF in MLflow's webhook delivery lets attackers pivot into cloud metadata endpoints and steal credentials. WatchTowr's honeypot network caught scanning starting within hours of the CVE going public.