Summary:
- Attackers are actively exploiting a Server-Side Request Forgery (SSRF) vulnerability within the MLflow machine learning platform to gain unauthorized access to internal environments.
- The exploit allows malicious actors to bypass security controls, potentially leading to data exfiltration or the compromise of sensitive infrastructure associated with AI/ML workflows.