MLflow Exploitation, NetScaler Emergency Patch, and European Banking Trojan

MLflow Exploitation, NetScaler Emergency Patch, and European Banking Trojan

•

Episode description

MLflow Exploitation, NetScaler Emergency Patch, and European Banking Trojan

CISA has confirmed active exploitation of a critical MLflow vulnerability, demanding immediate action from any organisation running AI or machine learning infrastructure. The server-side request forgery flaw allows attackers to access internal systems, and deployment patterns mean the platform often sits outside normal security review cycles. Separately, Citrix has issued an urgent advisory for NetScaler Gateway and ADC vulnerabilities, with language reflecting high exploitation likelihood. The perimeter-facing nature of these widely deployed remote access solutions makes them priority targets. Finally, the Manic Android banking trojan is spreading across Europe with a relay-based exfiltration capability that partially defeats network controls, raising BYOD security questions for UK small businesses. The NCSC has also published new guidance on managing agentic AI cyber risk, connecting to broader concerns about autonomous systems acting on behalf of users without adequate security review.

Chapters

  • Introduction Mauven opens with three stories requiring immediate action: a CISA-confirmed active exploitation, an urgent Citrix advisory, and a European banking malware threat relevant to UK businesses.
  • MLflow Under Active Exploitation CISA adds MLflow to the Known Exploited Vulnerabilities catalogue following confirmed active attacks. The server-side request forgery vulnerability affects AI and machine learning deployments that often sit outside normal security review cycles, creating exposure many organisations may not be aware of.
  • Call to Action Listeners are encouraged to follow the show and share the briefing, particularly with those managing IT for small businesses who need urgent awareness of the MLflow exploitation.
  • Citrix NetScaler Emergency Advisory Citrix issues urgent patching guidance for NetScaler Gateway and ADC vulnerabilities. The perimeter-facing nature of these widely deployed products, combined with Citrix’s deliberate use of emergency language, signals high exploitation risk requiring immediate verification with IT providers.
  • Manic Android Malware in Europe The Manic banking trojan spreads across Europe with relay-based exfiltration capability that routes stolen data through nearby infected devices, partially defeating network controls. BYOD practices in UK small businesses create exposure when personal Android devices access work accounts.
  • NCSC Guidance on Agentic AI The NCSC publishes guidance on managing cyber risk from autonomous AI systems that act on behalf of users. Prompt injection attacks against agentic AI tools represent an escalating threat as these systems gain access to business accounts and services.
  • Closing Mauven connects the common thread across all stories: security gaps emerge when deployment outpaces security review. The practical priority is knowing what runs in your environment, who manages it, and how responsibility is verified.

Links

No chapters are available for this episode.