Blog · 2 posts
#non-human-identity
- News · Aug 18, 2026An MLflow SSRF reaches cloud metadata services, and scanning started within hours
CVE-2026-64849 (CVSS 9.3) abuses MLflow's model-registry webhooks to proxy requests into internal services, including cloud metadata endpoints that hand out credentials. Fixed in 3.15.0; exploitation began the day of assignment.
- News · Aug 11, 2026GhostSplice splits a malicious instruction across MCP tool calls, and refusal rates go to zero
ASSET Research Group fragmented an exfiltration request across MCP channels so no single piece looked malicious. Models that refused the intact instruction 100 percent of the time complied 100 percent of the time when it arrived in parts.