The Cybersecurity and Infrastructure Security Agency (CISA) has warned federal agencies that threat actors are actively exploiting a critical vulnerability in MLflow, an open-source AI engineering platform.
CISA issued the alert after detecting active exploitation of the flaw in the wild. The vulnerability affects MLflow's core functionality, potentially allowing attackers to execute arbitrary code and gain unauthorized access to systems running the platform.
Federal agencies have been directed to patch affected systems immediately. Organizations using MLflow in production environments should prioritize applying the available security updates.
MLflow is widely deployed across enterprises for managing machine learning workflows and model deployment. The platform's popularity in AI operations makes this vulnerability a significant concern for organizations relying on its infrastructure.
The agency did not disclose specific technical details about the exploitation method, but emphasized the severity of the threat. Additional guidance for remediation is available on CISA's website. Organizations unable to patch immediately should consider implementing compensating controls and network segmentation to limit exposure.
AliExpress deploys silent WebAudio fingerprinting on its website that interferes with Bluetooth multipoint functionality on user devices. The script runs without explicit user consent.
Citrix has issued an urgent warning for administrators to patch two vulnerabilities affecting NetScaler Gateway and NetScaler ADC appliances. The flaws pose immediate security risks to remote access and networking infrastructure.
A new Android malware called Manic is targeting users across multiple European countries and uses a novel data exfiltration method through nearby infected devices.
Security defenses effectively block known attack methods but often fail against behavioral variants that achieve the same objectives through different techniques, according to Picus Security's Blue Report 2026.