A critical unauthenticated SSRF in MLflow's webhook delivery lets attackers pivot into cloud metadata endpoints and steal credentials. WatchTowr's honeypot network caught scanning starting within hours of the CVE going public.
A critical unauthenticated SSRF in MLflow's webhook delivery lets attackers pivot into cloud metadata endpoints and steal credentials. WatchTowr's honeypot network caught scanning starting within hours of the CVE going public.
A server-side request forgery vulnerability in LMDeploy's vision-language image loader let attackers reach cloud instance metadata services and harvest full credentials. The first confirmed exploitation hit Sysdig's honeypot less than 13 hours after the CVE dropped.
GreyNoise honeypots captured 91,403 attack sessions targeting enterprise LLM endpoints across two distinct campaigns between October 2025 and January 2026. One campaign fingerprinted 73+ model endpoints across all major AI providers. The other exploited SSRF vulnerabilities in Ollama and Twilio integrations.
Varonis Threat Labs chained three bugs in Microsoft 365 Copilot Enterprise Search to build a one-click exfiltration path that pulls emails, files, and live MFA codes without any OAuth prompt or user consent beyond clicking a Microsoft-domain URL.
CVE-2026-31204: an SSRF vulnerability in Ollama allows local-network attackers to read arbitrary files and reach internal services via the model pull endpoint. All versions affected.