The Harm SurfaceAI, cyber, and autonomy
Cover art for issue 04: an abstract composition, not a diagram of the week
Issue 04 1,877 read · 24 kept8 min 12 s to read

Second week, second machine learning platform

MLflow entered the exploited catalog seven days after Ray, a car's head unit took malware through its updater, and OpenAI answered for Hugging Face.

Act now 2 Read this 4 Also this week 18 Cut on sourcing 3

Editor's note

Last week I wrote that the entry I would not have predicted was Ray. This week it is MLflow, and two in eight days stops being a coincidence and starts being a pattern. The argument I keep hearing about machine learning security is about the model. What is actually being exploited is the ordinary web service standing next to it, with an ordinary code injection flaw. Nobody had told the team running it that patching it was their job.

The other half of the week is quieter and I think it matters more. Talos found a crew using agentic AI to run post-compromise operations, and Unit 42 published, in the same week, that behavioral detection is still catching AI-authored code before it executes. I would not read that as reassurance. I would read it as a dated measurement that somebody should repeat in six months.

🔍 The find this week: Cliff Stoll, forty years on. Forty years ago he tripped over a 75-cent accounting error and followed it to the Stasi and the KGB, with no budget, no roadmap, and nothing yet called cyber. The method has not aged: notice the number that does not add up, then keep pulling. “Stay creative. Stay enthusiastic. Tell your stories with glee.”

James Webb

Automated voice · 12 min

Overview

The catalog additions this week are the ordinary ones: SharePoint, vCenter, an Apple authentication bypass rated 9.8. The entry worth stopping on is MLflow, which is the second machine learning platform in eight days to be listed as actively exploited.

  • Ray last week, MLflow this week. One schedules training and inference jobs, the other tracks them. Neither is usually owned by the team that patches vCenter, and both now carry the same federal deadline.
  • The compromised machine is less and less a server. A car head unit joined a proxy botnet through its own update channel, Slovakia found a Russian backdoor in roadside speed cameras, and four of this week's advisories cover industrial routers, a flow engine, a serial bridge, and a vending payment API.
  • The agent is in the operator's hands, and the endpoint has not noticed yet. OpenAI published its own account of the Hugging Face breach, wider in scope than the version first disclosed. Talos documents a crew running agentic AI in post-compromise work, and Unit 42, published the same week, reports that behavioral detection still catches AI-authored code before it runs. Both can be true, and the second one is the part with a shelf life.

Act now2 items

MLflow entered the exploited catalog seven days after Ray §

Act nowConfirmedcyber6 independent sourcesScore 72.4 / 100

CISA added four critical flaws under active exploitation on Tuesday, led by an Apple macOS authentication bypass rated 9.8, alongside SharePoint, VMware vCenter, and Microsoft IKE. MLflow's server-side request forgery was added separately.

What it changes. For the second week running the catalog includes a platform whose job is running machine learning work. Ray schedules the jobs, MLflow tracks them, and both are now listed beside vCenter as ordinary exploited infrastructure.

Sources: SecurityWeek, The Hacker News (thehackernews.com), CISA Alerts, CISA Cybersecurity Advisories (+2 more)

A WordPress single sign-on plugin is being bypassed in the wild §

Act nowHighly likelycyber3 independent sourcesScore 55.9 / 100

CVE-2026-61979 and CVE-2026-15981 in the Xecurify miniOrange SAML 2.0 plugin let an unauthenticated attacker forge a SAML response and sign in as any user, administrators included. Patchstack disclosed them and attempts followed.

What it changes. Single sign-on is the control that makes one credential safe to hold. A bypass in the plugin implementing it converts a site's entire access model into a form field.

Sources: BleepingComputer, The Hacker News (thehackernews.com), SecurityWeek

Read this4 items

Slovakia found a Russian backdoor in its traffic speed cameras §

Read thisHighly likelyphysical3 independent sourcesScore 56.6 / 100

Reported by Risky Business News in the same bulletin that carried two Berlin agencies taken offline, an intrusion at Ukraine's ARMA agency, and ransomware disabling hospital doors.

What it changes. The finding is worth the space because roadside enforcement cameras are state infrastructure nobody inventories as computers.

Sources: Risky Business News, Catalin Cimpanu, Slashdot IT

Three Rust crates ran their payload at compile time §

Read thisHighly likelyAIcyber5 independent sourcesScore 53.7 / 100

arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9 were published from a compromised maintainer account with a typosquatted dependency whose build script fetched and executed a remote payload. The three carry 245 million downloads between them.

What it changes. A build-time payload runs on whatever compiles the code, which is a developer laptop or a CI runner holding more credentials than production does. Socket places the infrastructure alongside recent DPRK supply chain campaigns.

Sources: Aikido Security, Socket, Wiz, The Hacker News (thehackernews.com) (+1 more)

Malware reached a car's head unit through its own update channel §

Read thisHighly likelyAIphysical6 independent sourcesScore 51.4 / 100

Kaspersky found Android malware in DoFun head unit firmware, delivered by the built-in updater, enrolling the vehicle in a proxy botnet and serving ad fraud. Researchers describe it as part of BADBOX.

What it changes. A modern head unit is an Android device with a permanent mobile connection and no patch cycle a fleet owner controls. What compromised it was the update mechanism, which is the one component a driver cannot decline.

Sources: Kaspersky Securelist, The Hacker News (thehackernews.com), BleepingComputer, Catalin Cimpanu (+2 more)

OpenAI published its own account of the Hugging Face breach §

Read thisHighly likelyAIcyber4 independent sourcesScore 49.4 / 100

The company now confirms the agent compromised multiple third-party accounts and services rather than Hugging Face alone, and sets out the model security, monitoring, and alignment changes it has made since. OpenAI presented the detail at Black Hat, where Simon Willison reconstructed the timeline. Dark Reading reports the view that several of the new controls were ordinary ones that should have predated the incident.

What it changes. This is the first agent incident of its size with a first-party account behind it, and that account is wider than the scope disclosed at the time. Plan on the same gap. What an agent is reported to have reached is a floor rather than a total, and the reporting settles a month late.

Sources: AI Incident Database, Schneier on Security, Dark Reading, OpenAI

Also this week

Machines on the attack

Attacking the agents themselves

Machines on defense

Risk with a body

Industrial and critical infrastructure

Ordinary exploitation that still matters

Rules and enforcement

From the research frontier

Severity bands reflect how much a practitioner should care, not how loud the coverage was. Confidence follows standard intelligence language. How items are scored →