The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a serious vulnerability in the MLflow open-source AI engineering platform. This vulnerability is currently being exploited by hackers, posing a significant risk to federal agencies that use the software. MLflow is widely used for managing machine learning projects, and the exploitation could lead to unauthorized access or manipulation of sensitive data. Agencies are urged to take immediate action to secure their systems and protect against potential attacks. The situation emphasizes the need for organizations to stay vigilant and update their software regularly to guard against emerging threats.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
The Hacker News
Security researchers from Cycode have discovered significant vulnerabilities in the AIT-GUI, which is NASA's browser-based operator console for the AMMOS Instrument Toolkit. These flaws allow unauthenticated attackers to send arbitrary commands to spacecraft and instrument command buses. The vulnerabilities, assigned the identifier GHSA-p9r8-2q67-fp86, have a high severity rating of 9.4 on the CVSS scale, indicating they pose a serious risk. This situation is alarming as it could potentially allow unauthorized access to critical spacecraft operations, which could disrupt missions or lead to unintended consequences. Organizations using AIT-GUI should prioritize addressing these vulnerabilities to safeguard their systems.
A recent advisory from the US government has alerted industrial control system (ICS) operators to a new type of threat targeting Siemens S7 Series programmable logic controllers (PLCs). According to the advisory, attackers are using AI-generated scripts to exploit vulnerabilities in these exposed systems. This raises significant concerns for industries relying on these PLCs, as the potential for disruption or damage to critical infrastructure is high. Siemens PLCs are widely used in manufacturing and utilities, making them attractive targets for cybercriminals. Operators are urged to assess their security measures and ensure that their systems are properly protected against these AI-driven attacks.
OpenAI has implemented significant changes to its model security protocols following concerns raised by the Hugging Face incident and the discovery of advanced features in the Astra model. The new measures include a sandboxing approach to isolate models during testing, a system that sends alerts every 30 minutes during model training, and enforced pauses in training to address any emerging issues. These steps aim to enhance the overall security of OpenAI's machine learning models and mitigate potential risks associated with their capabilities. This overhaul is crucial as it addresses vulnerabilities that could be exploited by malicious actors, ensuring safer deployment of AI technologies.
A new Android malware called Manic has emerged, targeting users across several European countries. This malware is particularly concerning because it can exfiltrate data not just through traditional means, but also by leveraging nearby infected devices. This makes it more difficult for users to detect and defend against. Researchers have identified the malware's ability to communicate with other compromised devices, potentially allowing attackers to gather sensitive information from a wider network of victims. This situation raises alarms about the security of Android devices and the need for users to be vigilant about app permissions and device security.
Schneier on Security
In Wapello County, Iowa, a policy regarding the use of Flock license plate reader cameras has come to light, revealing that police are instructed to keep their usage a secret from the public. The policy explicitly directs officers not to mention the Automated License Plate Recognition (ALPR) technology to individuals during stops or in their reports unless absolutely necessary. This raises concerns about transparency and accountability in law enforcement practices. The use of such surveillance tools without public awareness parallels past incidents involving IMSI-catchers, which were similarly concealed. The implications of this secrecy affect public trust and raise questions about the balance between security and individual rights.
CERT Polska has alerted users that a serious vulnerability in Zimbra Collaboration Suite (ZCS) is currently being exploited by attackers. This flaw allows for remote code execution, which means that unauthorized individuals could potentially take control of affected systems. Organizations using ZCS should be particularly vigilant as this vulnerability poses a significant risk to their data and operations. Users are advised to check for updates and apply any available patches immediately to mitigate the risk. The situation is urgent as the exploitation of this vulnerability is already occurring in the wild, making timely action crucial for affected organizations.
After attending the Def Con hacking conference, participants found themselves at the center of a sophisticated phishing campaign. Researchers from Huntress reported receiving targeted emails that attempted to deceive them into revealing sensitive information. These phishing attempts were not just random; they were persistent and tailored to exploit the knowledge and skills of conference attendees. This incident serves as a reminder of the ongoing risks faced by cybersecurity professionals, especially after major events where attackers may leverage the excitement and connections made during the conference. The implications are significant, as such attacks can lead to data breaches or identity theft if successful.
Help Net Security
OpenAI is introducing a new system called Private Safety Processing, aimed at enhancing privacy and security as AI technology continues to develop. This system is designed to detect patterns in user interactions while ensuring that OpenAI staff cannot access the actual content of those interactions. The initiative is in response to concerns from early customers about data protection and misuse of AI systems. OpenAI plans to roll out this system and release a technical white paper in September to provide further details. This move reflects a collaborative approach to addressing the challenges posed by advanced AI capabilities, emphasizing that no single company can tackle these risks alone.
U.S. federal agencies, including the NSA, CISA, and FBI, have issued a warning about the use of artificial intelligence by cybercriminals to create exploit scripts aimed at Siemens S7 Series programmable logic controllers (PLCs). These PLCs are integral to the operation of critical infrastructure, managing functions in sectors like water treatment, energy production, and manufacturing. The advisory highlights the risk posed by these AI-driven attacks, particularly as these controllers are often exposed to the internet. If compromised, attackers could potentially disrupt essential services, leading to severe consequences for public safety and operational stability. Organizations using Siemens PLCs are urged to enhance their security measures to guard against these evolving threats.
Security Affairs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a serious vulnerability in MLflow, identified as CVE-2026-64849, to its Known Exploited Vulnerabilities catalog. This flaw is categorized as a server-side request forgery (SSRF) with a high CVSS score of 9.3, indicating its potential severity. MLflow, which is used for machine learning lifecycle management, could allow attackers to manipulate server requests, potentially leading to unauthorized access or data exposure. Organizations utilizing MLflow should prioritize addressing this vulnerability to safeguard their systems. Given the critical nature of the flaw, it is essential for users to assess their exposure and implement necessary security measures promptly.
The Hacker News
Researchers have discovered 40 malicious Firefox extensions that impersonate popular Web3 products, including OKX, Rabby Wallet, and TronLink, to steal users' cryptocurrency wallet information. The Socket Threat Research team identified these extensions as part of a larger group of 77 browser add-ons sharing similar code and infrastructure. This campaign, named Offside Wallet Theft Factory, poses a significant risk to individuals using these extensions, as they may unknowingly compromise their sensitive wallet credentials. Users of Firefox who have installed these extensions should remove them immediately to protect their assets. The incident serves as a reminder of the ongoing risks associated with browser extensions and the importance of verifying the legitimacy of such tools before installation.
Security Affairs
The US has charged 17 Iranian nationals linked to a cyber espionage campaign that lasted several years and resulted in the theft of 31 terabytes of data from various universities, companies, and government agencies around the world. This recent indictment, which adds eight new names to an earlier list, is part of ongoing efforts by US prosecutors to hold accountable those behind the attacks attributed to the Mabna Institute. The stolen data includes sensitive research and intellectual property, which could pose significant risks to national security and academic integrity. The indictment serves as a reminder of the persistent threat posed by state-sponsored hacking groups and highlights the need for enhanced cybersecurity measures across vulnerable sectors.
SecurityWeek
A serious vulnerability has been identified in Citrix NetScaler, allowing remote attackers to bypass authentication without needing any user interaction. This flaw is classified as critical, which raises significant concerns for organizations using this system. If exploited, attackers could gain unauthorized access to sensitive data or systems, putting many companies at risk. Citrix has released a patch to address this issue, and it's crucial for users to apply it immediately to protect their environments. The potential for exploitation means that organizations should prioritize this update to prevent unauthorized access.
A serious vulnerability identified as CVE-2026-19478 has been discovered in GitLab, allowing attackers to exploit it without needing authentication. This flaw enables unauthorized users to modify or delete public projects and user data, posing a significant risk to organizations that rely on GitLab for their development processes. Shortly after its disclosure, reports indicated that the vulnerability was actively being exploited, heightening concerns for users. Companies using GitLab should take immediate action to safeguard their data and projects. The situation emphasizes the need for prompt updates and vigilance regarding security practices.