threat-intel ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More This week saw a surge in high-impact cyberattacks and vulnerabilities, highlighting the increasing sophistication and speed of threat actors. AI is now being weaponized to craft exploit scripts targeting Siemens PLCs, while GitLab, Stripe, and numerous other platforms suffered attacks. A new Zombie Card attack bypasses… The Hacker News · 6d ago High CVE-2026-19478CVE-2021-27101CVE-2023-34362UNRUvulnerabilitysupply-chainransomware
vulnerability MLflow Vulnerability Exploited for Cloud Credential Theft A vulnerability in MLflow, a popular AI engineering platform, has been exploited by threat actors to steal cloud credentials and secrets. The flaw, tracked as CVE-2026-64849, allows unauthenticated SSRF attacks, leading… SecurityWeek · Aug 20, 2026 Critical CVE-2026-64849ssrfcloudmlflow
threat-intel Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets Two critical vulnerabilities are being actively exploited to steal cloud credentials and secrets. MLflow (versions < 3.15.0) is experiencing SSRF attacks, allowing attackers to access cloud metadata and exfiltrate sensit… The Hacker News · Aug 18, 2026 Critical CVE-2026-64849CVE-2026-25895CVE-2026-25939ssrfpath traversalremote code execution