All CosmicBytez Labs articles tagged #Machine Learning, across news, security advisories, how-to guides, and projects.
CVE-2026-64849 (CVSS 9.3): Active SSRF exploitation in MLflow lets attackers steal AWS cloud credentials via redirect bypass. Added to CISA KEV.
Critical unauthenticated SSRF in MLflow's webhook system lets attackers redirect requests to steal AWS credentials. Upgrade to 3.15.0.
A critical CVSS 9.9 vulnerability in the Feast ML feature store allows unauthenticated remote code execution through malicious user-defined functions serialized with the Python dill library and stored in the feature registry.
OpenAI's unreleased Astra model has produced machine-verified proofs for 10 open mathematical problems — some unsolved for over four decades — at a total compute cost of roughly $2,000.
A critical logic flaw in sentence-transformers' import_module_class helper allows attackers to bypass trust_remote_code=False and achieve arbitrary code execution by placing malicious files in a model directory on disk. CVSS 9.8.
Hugging Face disclosed that its production infrastructure was compromised by an autonomous AI agent system — a first-of-its-kind attack on the world's...
Anthropic has extended free access to Claude Fable 5 for paid subscribers until July 19, giving users an additional week with the company's most powerful...
OpenAI has temporarily lifted rate limits on GPT-5.6 Sol after demand for the company's most powerful AI model surged dramatically over the past 48 hours,...
As OpenAI and Anthropic push frontier AI capabilities forward, SentinelOne argues that AI-native, machine-speed cyber defense is now essential — and that the…
A critical path traversal vulnerability in MLflow's extract_archive_to_dir function allows attackers to write arbitrary files outside the intended...