Microsoft Brings App Building Capabilities to Copilot Cowork and Studio

Microsoft Copilot Cowork and Copilot Studio now support the agentic creation of apps using natural language.
The post Microsoft Brings App Building Capabilities to Copilot Cowork and Studio appeared first on Thurrott.com.
Continue reading Microsoft Brings App Building Capabilities to Copilot Cowork and Studio

VU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization control

Overview

A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies the control based on the model path’s file extension, and the statsmodels flavor does not apply the control.

Description

MLflow is an open-source platform for managing machine learning lifecycles, including model packaging, versioning, and deployment. “Flavors” refer to the specialized frameworks through which supported models are stored and loaded. In response to previous vulnerability concerns, MLflow implemented the MLFLOW_ALLOW_PICKLE_DESERIALIZATION safety control to block and disable executing any pickle deserialization and subsequent loads per the user’s choice.

When loading models through mlflow.pyfunc.load_model(model), users must specify a model flavor and path in an MLmodel file. With the dspy flavor, MLflow checks the value of MLFLOW_ALLOW_PICKLE_DESERIALIZATION, and whether the specified model path ends in .pkl. A model path that does not end in .pkl (even if the file is actually a pickle file), will route to a separate branch for pickle deserialization, bypassing the safety control. However, when loading through the statsmodels flavor, there is no check for MLFLOW_ALLOW_PICKLE_DESERIALIZATION at all.

Impact

Exploitation of this vulnerability allows for arbitrary remote code execution through a malicious pickle-loaded payload, regardless of a user explicitly disallowing pickle serialization, through vulnerable flavor specifications in the MLmodel configuration file. The attack path requires write access to any location from which a user obtains MLflow models. This vulnerability was confirmed against MLflow 3.12.0.

Solution

MLFlow could not be reached to coordinate this vulnerability; however, the statsmodels flavor was patched in versions >= 3.15.0. Users should upgrade immediately. Until a further fix remedying the dspy flavor vulnerability is available, MLflow users who wish to block pickle deserialization and loads should avoid loading any models via the dspy flavor.

Acknowledgements

Thanks to Prasanna Dabi for reporting this vulnerability. This document was written by Alex Lewis.

Continue reading VU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization control

Posted in Uncategorized

First Agentic AI Data Breach Reported to Spanish Regulator

Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous cyberattacks.
The post First Agentic AI Data Breach Reported to Spanish Regulator appea… Continue reading First Agentic AI Data Breach Reported to Spanish Regulator

AirPods 5: Should You Pay $20 More for the Wireless Charging Case?

The $149 AirPods 5 add stem volume control, broader charging support, a Find My case speaker, and longer battery life over the $129 version.
The post AirPods 5: Should You Pay $20 More for the Wireless Charging Case? appeared first on TechRepublic.
Continue reading AirPods 5: Should You Pay $20 More for the Wireless Charging Case?

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation.

The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9…. Continue reading Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

Posted in Uncategorized