Threat Intelligence

Hackers Actively Exploiting AI and Industrial Software Flaws to Steal Cloud Credentials

The Hacker News · 19 Aug 2026
Key Takeaway If your business uses MLflow, FUXA, or similar open-source platforms, apply available security patches immediately and review who can access these systems from the internet.

Cybersecurity researchers at watchTowr and VulnCheck have identified active, real-world exploitation attempts targeting two critical vulnerabilities in widely used open-source software. The first affects MLflow, a popular platform used by organisations to build and manage artificial intelligence models. The flaw is a server-side request forgery (SSRF) vulnerability that attackers can exploit to trick the system into revealing sensitive cloud credentials and other secrets stored on the server.

The second vulnerability affects FUXA, an open-source tool used to monitor and control industrial equipment such as factory machinery and utility systems. Because FUXA is used in operational technology environments, a successful attack could potentially disrupt physical processes or give attackers a foothold into sensitive industrial networks.

Both vulnerabilities are being actively scanned for and exploited in the wild, meaning organisations using these tools face genuine, ongoing risk rather than a theoretical threat. Australian small businesses that rely on AI development platforms or industrial control software, even indirectly through vendors or partners, should treat this as a reminder that open-source tools require the same security diligence as commercial products.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.